REDHAT-BUG-750645: Low severity wireshark vulnerability
A flaw in the Infiniband dissector could cause Wireshark 1.4.0 through 1.4.9 and 1.6.0 through 1.6.3 to crash by dereferencing a NULL pointer by reading a malformed packet trace file or if someone were to inject a malformed packet onto the wire. This is corrected in wireshark 1.6.3
References:
https://bugs.wireshark.org/bugzilla/showbug.cgi?id=6476 http://anonsvn.wireshark.org/viewvc?view=revision&revision=39500
External References:
http://www.wireshark.org/security/wnpa-sec-2011-18.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-750645?
REDHAT-BUG-750645 is classified as a moderate severity vulnerability due to its potential to cause application crashes.
How do I fix REDHAT-BUG-750645?
To fix REDHAT-BUG-750645, upgrade Wireshark to version 1.6.3 or later.
What versions of Wireshark are affected by REDHAT-BUG-750645?
Wireshark versions 1.4.0 to 1.4.9 and 1.6.0 to 1.6.3 are affected by REDHAT-BUG-750645.
What is the impact of exploiting REDHAT-BUG-750645?
Exploiting REDHAT-BUG-750645 could lead to a crash of the Wireshark application.
Is there a workaround for REDHAT-BUG-750645?
There is no known workaround for REDHAT-BUG-750645, so upgrading is the recommended solution.