CVE-2014-6427: Buffer Overflow
Off-by-one error in the isrtsprequestorreply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers parsing of a token located one position beyond the current position.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6427?
CVE-2014-6427 has a severity rating that may result in a denial of service due to a remote application crash.
How do I fix CVE-2014-6427?
To fix CVE-2014-6427, upgrade your Wireshark version to 1.10.10 or 1.12.1 or later.
Which versions of Wireshark are affected by CVE-2014-6427?
CVE-2014-6427 affects Wireshark versions from 1.10.0 to 1.10.9 and 1.12.0.
What type of attack can exploit CVE-2014-6427?
CVE-2014-6427 can be exploited by remote attackers sending crafted packets to cause a denial of service.
Is CVE-2014-6427 a critical vulnerability?
CVE-2014-6427 is not classified as critical, but it poses a risk of application instability.