|
|
| |
| Wireshark is prone to a denial-of-service vulnerability because it fails to properly handle specially crafted IKE packets. |
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/49377
|
| |
Vulnerable Systems:
* Wireshark Wireshark 1.6.1
* Wireshark Wireshark 1.6
* Wireshark Wireshark 1.4.8
* Wireshark Wireshark 1.4.7
* Wireshark Wireshark 1.4.6
* Wireshark Wireshark 1.4.5
* Wireshark Wireshark 1.4.4
* Wireshark Wireshark 1.4.3
* Wireshark Wireshark 1.4.2
* Wireshark Wireshark 1.4.1
* Wireshark Wireshark 1.4.1
* Wireshark Wireshark 1.4.0
Immune Systems:
* Wireshark Wireshark 1.6.2
* Wireshark Wireshark 1.4.9
An attacker can exploit this issue to trigger an infinite loop, which causes the affected application to crash, denying service to legitimate users.
Vendor Status:
Wireshark had issued an update for this vulnerability
Patch Availability:
http://www.wireshark.org/download.html
CVE Information:
CVE-2011-3266
Disclosure Timeline:
Initial Release: Jul 30 2011
|
|
blog comments powered by
|