CVE-2012-4289: Low severity Wireshark Wireshark vulnerability
epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4289?
CVE-2012-4289 has been classified as a denial-of-service vulnerability, allowing remote attackers to consume CPU resources.
How do I fix CVE-2012-4289?
To mitigate CVE-2012-4289, upgrade Wireshark to versions 1.4.15, 1.6.10, or 1.8.2 or later.
What versions of Wireshark are affected by CVE-2012-4289?
CVE-2012-4289 affects Wireshark versions 1.4.0 through 1.4.14, 1.6.0 through 1.6.9, and 1.8.0 through 1.8.1.
What type of attack does CVE-2012-4289 facilitate?
CVE-2012-4289 allows attackers to launch denial-of-service attacks by causing an infinite loop through a large number of ACL entries.
Is CVE-2012-4289 exploitable remotely?
Yes, CVE-2012-4289 can be exploited remotely, allowing attackers to overwhelm the affected Wireshark instance.