REDHAT-BUG-710184: Null Pointer Dereference
A NULL pointer dereference flaw was found in the way Wireshark processed certain Diameter dictionary files. A remote attacker could create a specially-crafted dictionary file, which once used, by a local, unsuspecting user when loading a Diameter capture file could lead to wireshark application crash.
References: [1] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [2] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-710184?
The severity of REDHAT-BUG-710184 is considered to be high due to the potential for remote code execution.
How do I fix REDHAT-BUG-710184?
To fix REDHAT-BUG-710184, update Wireshark to the latest version that addresses this vulnerability.
What causes the vulnerability identified in REDHAT-BUG-710184?
The vulnerability in REDHAT-BUG-710184 is caused by a NULL pointer dereference when processing certain Diameter dictionary files.
Can REDHAT-BUG-710184 be exploited by an attacker?
Yes, a remote attacker can exploit REDHAT-BUG-710184 by crafting a malicious Diameter dictionary file.
Who is affected by REDHAT-BUG-710184?
REDHAT-BUG-710184 affects users of Wireshark who process Diameter capture files.