CVE-2012-4048: Code Injection
The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4048?
CVE-2012-4048 has a severity rating that indicates a potential denial of service vulnerability.
How do I fix CVE-2012-4048?
To fix CVE-2012-4048, upgrade Wireshark to versions 1.4.14, 1.6.9, or 1.8.1 or later.
What software is affected by CVE-2012-4048?
CVE-2012-4048 affects multiple versions of Wireshark including 1.4.x prior to 1.4.14, 1.6.x prior to 1.6.9, and 1.8.x prior to 1.8.1.
What kind of attacks can exploit CVE-2012-4048?
CVE-2012-4048 can be exploited by sending crafted packets that cause an application crash due to invalid pointer dereference.
Is there a workaround for CVE-2012-4048?
There is no effective workaround for CVE-2012-4048, so upgrading to a fixed version is recommended.