CVE-2012-5237: Low severity wireshark vulnerability
Published Oct 4, 2012
·Updated
The dissecthsrp function in epan/dissectors/packet-hsrp.c in the HSRP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Affected Software
3 affected components
Wireshark Wireshark=1.8.0
Wireshark Wireshark=1.8.1
Wireshark Wireshark=1.8.2
Remediation
Event History
Oct 4, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5237?
CVE-2012-5237 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2012-5237?
To fix CVE-2012-5237, upgrade Wireshark to version 1.8.3 or later.
3
What software versions are affected by CVE-2012-5237?
CVE-2012-5237 affects Wireshark versions 1.8.0, 1.8.1, and 1.8.2.
4
What type of attack does CVE-2012-5237 facilitate?
CVE-2012-5237 allows attackers to cause a denial of service through an infinite loop triggered by a malformed packet.
5
Where in the code does CVE-2012-5237 occur?
CVE-2012-5237 is found in the dissect_hsrp function within the packet-hsrp.c file of Wireshark.