Wireshark Frame Metadissector CVE-2014-4020 Denial of Service Vulnerability
BID:68044
Info
Wireshark Frame Metadissector CVE-2014-4020 Denial of Service Vulnerability
| Bugtraq ID: | 68044 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-4020 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2014 12:00AM |
| Updated: | May 07 2015 05:15PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Wireshark Wireshark 1.10.7 Wireshark Wireshark 1.10.6 Wireshark Wireshark 1.10.5 Wireshark Wireshark 1.10.4 Wireshark Wireshark 1.10.3 Wireshark Wireshark 1.10.2 Wireshark Wireshark 1.10.1 Wireshark Wireshark 1.10 Wireshark Wireshark 1.10 Gentoo Linux |
| Not Vulnerable: |
Wireshark Wireshark 1.10.8 |
Discussion
Wireshark Frame Metadissector CVE-2014-4020 Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark 1.10.0 to 1.10.7 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark 1.10.0 to 1.10.7 are vulnerable.
Solution / Fix
Wireshark Frame Metadissector CVE-2014-4020 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark Frame Metadissector CVE-2014-4020 Denial of Service Vulnerability
References:
References:
- Wireshark 1.10.8 Release Notes (Wireshark)
- Wireshark Homepage (Wireshark)
- wnpa-sec-2014-07 · Frame metadissector crash (Wireshark)