CVE-2012-2393: Buffer Overflow
epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers incorrect memory allocation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2393?
CVE-2012-2393 has a severity rating of medium, as it can lead to application crashes and denial of service.
How do I fix CVE-2012-2393?
To fix CVE-2012-2393, upgrade Wireshark to versions 1.4.13 or 1.6.8 or later.
What types of applications are affected by CVE-2012-2393?
CVE-2012-2393 affects Wireshark versions 1.4.0 to 1.4.12 and 1.6.0 to 1.6.7.
What attack vector is used in CVE-2012-2393?
CVE-2012-2393 can be exploited remotely through a crafted packet sent to the vulnerable Wireshark application.
What are the consequences of exploiting CVE-2012-2393?
Exploiting CVE-2012-2393 may result in an application crash, causing denial of service.