CVE-2012-4297: Buffer Overflow
Buffer overflow in the dissectgsmrlcmacdownlink function in epan/dissectors/packet-gsmrlcmac.c in the GSM RLC MAC dissector in Wireshark 1.6.x before 1.6.10 and 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a malformed packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4297?
CVE-2012-4297 has a high severity rating due to the buffer overflow vulnerability that can allow remote code execution.
How do I fix CVE-2012-4297?
To fix CVE-2012-4297, update Wireshark to version 1.6.10 or later for 1.6.x series and 1.8.2 or later for 1.8.x series.
Which versions of Wireshark are affected by CVE-2012-4297?
CVE-2012-4297 affects Wireshark versions 1.6.0 to 1.6.9 and 1.8.0 to 1.8.1.
What type of attack can exploit CVE-2012-4297?
CVE-2012-4297 can be exploited by sending a malformed packet to the Wireshark application.
Is CVE-2012-4297 a local or remote vulnerability?
CVE-2012-4297 is a remote vulnerability, allowing attackers to execute arbitrary code from a remote location.