CVE-2012-4285: Low severity openSUSE openSUSE vulnerability
The dissectpft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4285?
CVE-2012-4285 has a severity rating that allows remote attackers to cause a denial of service through a divide-by-zero error.
How do I fix CVE-2012-4285?
To fix CVE-2012-4285, upgrade to Wireshark version 1.4.15, 1.6.10, or 1.8.2 or later.
Which versions are affected by CVE-2012-4285?
CVE-2012-4285 affects Wireshark versions prior to 1.4.15, 1.6.10, and 1.8.2.
What can a denial of service from CVE-2012-4285 allow an attacker to do?
A denial of service caused by CVE-2012-4285 can allow attackers to crash the Wireshark application.
Is there a workaround for CVE-2012-4285 if I cannot update?
The best course of action for CVE-2012-4285 is to update to a patched version, as there are no effective workarounds.