CVE-2014-6424: Buffer Overflow
The dissectv9v10pdudata function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized memory read and application crash) via a crafted packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6424?
CVE-2014-6424 has a severity rating that may lead to denial of service due to uninitialized memory reads.
How do I fix CVE-2014-6424?
To fix CVE-2014-6424, upgrade Wireshark to version 1.10.10 or 1.12.1 or later.
Which versions of Wireshark are affected by CVE-2014-6424?
CVE-2014-6424 affects Wireshark versions 1.10.0 to 1.10.9 and 1.12.0.
What type of vulnerability is CVE-2014-6424?
CVE-2014-6424 is a vulnerability that allows remote attackers to cause denial of service.
Can CVE-2014-6424 allow remote code execution?
No, CVE-2014-6424 primarily causes denial of service but does not allow remote code execution.