int(6425)

Vulnerability Bulletins


Denegación de servicio en Wireshark.

Vulnerability classification

Property Value
Confidence level Oficial
Impact Denegación de Servicio
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Wireshark 1.x

Description

Se ha descubierto una vulnerabilidad de denegación de servicio en Wireshark.

La vulnerabilidad reside en el disector del protocolo DRDA (epan/dissectors/packet-drda.c).

Un atacante remoto podría causar un bucle infinito, consumiendo así la totalidad de la CPU, mediante un paquete malicioso.

Solution

La vulnerabilidad ha sido solucionada en el código fuente, disponible en su repositorio oficial.

Standar resources

Property Value
CVE CVE-2012-3548
BID

Other resources

Bug 849926 - (CVE-2012-3548) CVE-2012-3548 wireshark (X >= 1.6.8): DoS (excessive CPU use and infinite loop) in DRDA dissector
https://bugzilla.redhat.com/show_bug.cgi?id=849926

Version history

Version Comments Date
1.0 Aviso emitido 2012-09-04