CVE-2012-2392: Low severity wireshark vulnerability
Published Jun 30, 2012
·Updated
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors.
Affected Software
22 affected components
Wireshark Wireshark=1.4.0
Wireshark Wireshark=1.4.1
Wireshark Wireshark=1.4.2
Wireshark Wireshark=1.4.3
Wireshark Wireshark=1.4.4
Wireshark Wireshark=1.4.5
Wireshark Wireshark=1.4.6
Wireshark Wireshark=1.4.7
Wireshark Wireshark=1.4.8
Wireshark Wireshark=1.4.9
Wireshark Wireshark=1.4.10
Wireshark Wireshark=1.4.11
Wireshark Wireshark=1.4.12
Wireshark Wireshark=1.4.13
Wireshark Wireshark=1.6.0
Wireshark Wireshark=1.6.1
Wireshark Wireshark=1.6.2
Wireshark Wireshark=1.6.3
Wireshark Wireshark=1.6.4
Wireshark Wireshark=1.6.5
Wireshark Wireshark=1.6.6
Wireshark Wireshark=1.6.7
Event History
Jun 30, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2392?
CVE-2012-2392 is classified as a denial of service vulnerability due to infinite loop conditions in certain dissectors.
2
How do I fix CVE-2012-2392?
To fix CVE-2012-2392, upgrade Wireshark to version 1.4.13 or later or 1.6.8 or later.
3
What versions of Wireshark are affected by CVE-2012-2392?
CVE-2012-2392 affects Wireshark versions 1.4.x prior to 1.4.13 and 1.6.x prior to 1.6.8.
4
Can CVE-2012-2392 be exploited remotely?
Yes, CVE-2012-2392 can be exploited remotely by attackers to cause denial of service.
5
What specific dissectors are related to CVE-2012-2392?
CVE-2012-2392 relates to vulnerabilities in the ANSI MAP, ASF, IEEE 802.11, IEEE 802.3, and LTP dissectors.