CVE-2012-5240: Buffer Overflow
Published Oct 4, 2012
·Updated
Buffer overflow in the dissecttlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet.
Affected Software
3 affected components
Wireshark Wireshark=1.8.0
Wireshark Wireshark=1.8.1
Wireshark Wireshark=1.8.2
Event History
Oct 4, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5240?
CVE-2012-5240 is classified as a denial of service vulnerability.
2
How do I fix CVE-2012-5240?
To fix CVE-2012-5240, update Wireshark to version 1.8.3 or later.
3
What versions of Wireshark are affected by CVE-2012-5240?
CVE-2012-5240 affects Wireshark versions 1.8.0, 1.8.1, and 1.8.2.
4
What kind of impact can CVE-2012-5240 have on systems?
CVE-2012-5240 can lead to application crashes or potentially other unspecified impacts.
5
Which function is responsible for the vulnerability in CVE-2012-5240?
The buffer overflow vulnerability in CVE-2012-5240 is found in the dissect_tlv function.