Buffer overflow in the MAC-LTE dissector (epan/dissectors/packet-mac-lte.c) in Wireshark 1.2.0 through 1.2.13 and 1.4.0 through 1.4.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of RARs.
Buffer overflow in the daintreesnaread function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.
Stack consumption vulnerability in the dissectberchoice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through 1.4.4 might allow remote attackers to cause a denial of service (infinite loop) via vectors involving self-referential ASN.1 CHOICE values.
Heap-based buffer overflow in the dissectldsstransfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
A heap-based buffer overflow was found in the way Wireshark processes signalling traces generated by Gammu (www.gammu.org) from Nokia DCT3 phones in Netmonitor mode.
An attacker could use this flaw to cause wireshark executable to crash or, potentially, execute arbitrary code with the privileges of the user running wireshark, if the local user opened a specially-crafted capture file.
The following upstream commit fixes this issue: http://anonsvn.wireshark.org/viewvc?view=rev&revision=35953
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0538 to the following vulnerability:
Name: CVE-2011-0538 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0538 Assigned: 20110120 Reference: MLIST:[oss-security] 20110204 Wireshark: Freeing uninitialized pointer Reference: URL:http://openwall.com/lists/oss-security/2011/02/04/1 Reference: MISC:https://srcm.symantec.com/EditVulnerabilityFixes.aspx?docId=549474 Reference: CONFIRM:https://bugs.wireshark.org/bugzilla/showbug.cgi?id=5652 Reference: BID:46167 Reference: URL:http://www.securityfocus.com/bid/46167
Wireshark 1.5.0, 1.4.3, and earlier frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed file.
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error. NOTE: some of these details are obtained from third party information.
Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors.
Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
Off-by-one error in the dissectnegprotresponse function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained from third party information.
Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.
Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.
epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (memory consumption) via (1) a long LDAP filter string or (2) an LDAP filter string containing many elements.
Multiple stack consumption vulnerabilities in the dissectmscompressedstring and dissectmscldapstring functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.
wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field.
It was found that Wireshark's DICOM dissector did not check for invalid payload data unit length. A remote attacker could create a specially-crafted capture file, which once opened, by a local, unsuspecting user could lead to wireshark application hang / termination.
References: [1] https://bugs.wireshark.org/bugzilla/showbug.cgi?id=5876 (upstream bug report) [2] http://www.wireshark.org/download/automated/captures/fuzz-2011-04-30-7272.pcap (public reproducer) [3] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [4] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
Upstream patch: [5] http://anonsvn.wireshark.org/viewvc?view=revision&revision=36958
A NULL pointer dereference flaw was found in the way Wireshark processed certain Diameter dictionary files. A remote attacker could create a specially-crafted dictionary file, which once used, by a local, unsuspecting user when loading a Diameter capture file could lead to wireshark application crash.
References: [1] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [2] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
A stack-based buffer over-read flaw was found in the way Wireshark performed management of testy, virtualizable buffers. A remote attacker could create a specially-crafted capture file, which once opened, by a local, unsuspecting user could lead to wireshark application crash.
References: [1] https://bugs.wireshark.org/bugzilla/showbug.cgi?id=5912 (upstream bug report) [2] https://bugs.wireshark.org/bugzilla/attachment.cgi?id=6335 (public reproducer) [3] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [4] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
Upstream patch: [5] http://anonsvn.wireshark.org/viewvc?view=revision&revision=37068
An integer underflow flaw, leading to heap-based buffer over-read was found in the Wireshark's Visual Networks dissector. A remote attacker could create a specially-crafted capture file, which once opened, by a local, unsuspecting user could lead to wireshark application crash.
References: [1] https://bugs.wireshark.org/bugzilla/showbug.cgi?id=5934 (upstream bug report) [2] https://bugs.wireshark.org/bugzilla/attachment.cgi?id=6366 (reproducer) [3] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [4] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
Upstream patch: [5] http://anonsvn.wireshark.org/viewvc?view=revision&revision=37128
A double free flaw was found in the way Wireshark uncompressed a zlib compressed packet inside a message of tvbuff buffer. A remote attacker could create a specially-crafted capture file, which once opened, by a local, unsuspecting user could lead to wireshark application crash.
References: [1] https://bugs.wireshark.org/bugzilla/showbug.cgi?id=5908 (upstream bug report, not public) [2] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [3] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
Upstream patch: [4] http://anonsvn.wireshark.org/viewvc?view=revision&revision=37081
The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.