First published: Sat Sep 20 2014(Updated: )
The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x before 1.12.1 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a CUPS packet that lacks a trailing '\0' character.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =1.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6425 is classified as a medium severity vulnerability that can lead to denial of service.
To fix CVE-2014-6425, upgrade to Wireshark version 1.12.1 or later.
CVE-2014-6425 can be exploited by remote attackers through manipulated CUPS packets.
CVE-2014-6425 affects Wireshark version 1.12.0 and earlier.
Exploitation of CVE-2014-6425 may result in application crashes due to buffer over-read.