CVE-2012-4294: Buffer Overflow
Published Aug 16, 2012
·Updated
Buffer overflow in the channelisedfillsdhg707format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.
Affected Software
3 affected components
Wireshark Wireshark=1.8.0
Wireshark Wireshark=1.8.1
Sun SunOS=5.11
Remediation
Event History
Aug 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4294?
CVE-2012-4294 has a critical severity rating as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2012-4294?
To fix CVE-2012-4294, upgrade Wireshark to version 1.8.2 or later.
3
Which versions of Wireshark are affected by CVE-2012-4294?
Versions of Wireshark 1.8.0 and 1.8.1 are affected by CVE-2012-4294.
4
What type of vulnerability is CVE-2012-4294?
CVE-2012-4294 is a buffer overflow vulnerability.
5
Can CVE-2012-4294 be exploited by local users?
CVE-2012-4294 can be exploited by remote attackers, not local users.