CVE-2014-6431: Buffer Overflow
Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers writes of uncompressed bytes beyond the end of the output buffer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6431?
CVE-2014-6431 has been classified as a high severity vulnerability due to its ability to cause denial of service through application crashes.
How do I fix CVE-2014-6431?
To fix CVE-2014-6431, upgrade Wireshark to version 1.10.10 or 1.12.1 or later, which addresses this buffer overflow.
What versions of Wireshark are affected by CVE-2014-6431?
CVE-2014-6431 affects Wireshark versions 1.10.0 to 1.10.9 and 1.12.0.
Can CVE-2014-6431 be exploited remotely?
Yes, CVE-2014-6431 can be exploited remotely by attackers using crafted files to trigger the vulnerability.
What kind of attack does CVE-2014-6431 enable?
CVE-2014-6431 enables denial of service attacks, resulting in application crashes when exploited.