REDHAT-BUG-750643: Low severity wireshark vulnerability
An uninitialized variable in the CSN.1 dissector in Wireshark 1.6.0 through 1.6.2 could cause Wireshark to crash by reading a malformed packet trace file or if someone were to inject a malformed packet onto the the wire. This is corrected in wireshark 1.6.3.
References:
https://bugs.wireshark.org/bugzilla/showbug.cgi?id=6351 http://anonsvn.wireshark.org/viewvc?view=revision&revision=39140
External References:
http://www.wireshark.org/security/wnpa-sec-2011-17.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-750643?
REDHAT-BUG-750643 is classified as a vulnerability that can lead to crashes, impacting the application's stability.
How do I fix REDHAT-BUG-750643?
To resolve REDHAT-BUG-750643, upgrade Wireshark to version 1.6.3 or later.
What versions of Wireshark are affected by REDHAT-BUG-750643?
Wireshark versions 1.6.0 to 1.6.2 are affected by REDHAT-BUG-750643.
What causes the vulnerability identified by REDHAT-BUG-750643?
The vulnerability in REDHAT-BUG-750643 is caused by an uninitialized variable in the CSN.1 dissector.
Can REDHAT-BUG-750643 be exploited by remote attackers?
Yes, REDHAT-BUG-750643 can be exploited by remote attackers through malformed packet traces.