CVE-2014-6432: Medium severity wireshark vulnerability
The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not prevent data overwrites during copy operations, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6432?
CVE-2014-6432 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2014-6432?
To fix CVE-2014-6432, update Wireshark to version 1.10.10 or later, or to version 1.12.1 or later.
Which versions of Wireshark are affected by CVE-2014-6432?
CVE-2014-6432 affects Wireshark versions 1.10.0 through 1.10.9 and 1.12.0.
What type of vulnerability is CVE-2014-6432?
CVE-2014-6432 is a vulnerability that allows remote attackers to cause a denial of service via crafted files.
Is CVE-2014-6432 easily exploitable?
Yes, an attacker can exploit CVE-2014-6432 by sending a specially crafted file to the affected Wireshark versions.