REDHAT-BUG-737783: Low severity wireshark vulnerability
An uninitialized variable flaw was found in the CSN.1 dissector of wireshark. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This affects versions 1.6.0 to 1.6.1 and has been fixed in version 1.6.2
Reference: http://www.wireshark.org/security/wnpa-sec-2011-16.html
This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories:
https://admin.fedoraproject.org/updates/FEDORA-2011-12423 https://admin.fedoraproject.org/updates/FEDORA-2011-12403 https://admin.fedoraproject.org/updates/FEDORA-2011-12399
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-737783?
REDAHT-BUG-737783 is classified as a medium severity vulnerability due to its potential to crash Wireshark.
How do I fix REDHAT-BUG-737783?
To fix REDHAT-BUG-737783, upgrade Wireshark to version 1.6.2 or later.
Which versions are affected by REDHAT-BUG-737783?
REDAHT-BUG-737783 affects Wireshark versions 1.6.0 to 1.6.1.
What type of flaw is REDHAT-BUG-737783?
REDAHT-BUG-737783 is an uninitialized variable flaw in the CSN.1 dissector of Wireshark.
Can REDHAT-BUG-737783 be exploited remotely?
Yes, REDHAT-BUG-737783 can potentially be exploited by injecting malformed packets onto the wire.