CVE-2012-4292: Input Validation
The dissectstunmessage function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4292?
CVE-2012-4292 is rated as a medium-severity vulnerability that can lead to denial of service.
How do I fix CVE-2012-4292?
To fix CVE-2012-4292, you should upgrade Wireshark to a version that is 1.4.15 or later, 1.6.10 or later, or 1.8.2 or later.
Which versions of Wireshark are affected by CVE-2012-4292?
The affected versions include Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2.
Can CVE-2012-4292 be exploited remotely?
Yes, CVE-2012-4292 can be exploited by remote attackers to cause a denial of service.
Is there a workaround for CVE-2012-4292?
No specific workaround is recommended for CVE-2012-4292; the best practice is to upgrade to a patched version.