Topic : | Wireshark 1.0.x Malformed .ncf packet capture Local Denial of Service
|
SecurityAlert : 4462
CVE : CVE-2008-4682
CWE : CWE-20
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Shinnok
Published : 23.10.2008
Affected Software : | wireshark:wireshark:0.99.7
wireshark:wireshark:0.99.8
wireshark:wireshark:1.0
wireshark:wireshark:1.0.0
wireshark:wireshark:1.0.1
wireshark:wireshark:1.0.2
wireshark:wireshark:1.0.3 |
 Advisory Content : Wireshark 1.0.x .ncf local denial of service
author: Shinnok
Description
Wireshark 1.0.x crashes as a result of a failed assertion when dealing
with a malformed Tamosoft CommView .ncf packet capture:
Err file wtap.c: line 620 (wtap_read): assertion failed:
(wth->phdr.pkt_encap != WTAP_ENCAP_PER_PACKET)
References :
http://www.securityfocus.com/bid/31838
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2926
http://www.wireshark.org/security/wnpa-sec-2008-06.html
http://www.milw0rm.com/exploits/6622
http://www.frsirt.com/english/advisories/2008/2872
http://securitytracker.com/id?1021069
http://secunia.com/advisories/32355
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|