3.3

CVE-2012-1594

Exploit
epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wireshark ≫ Wireshark Version 1.6.0
Wireshark ≫ Wireshark Version 1.6.1
Wireshark ≫ Wireshark Version 1.6.2
Wireshark ≫ Wireshark Version 1.6.3
Wireshark ≫ Wireshark Version 1.6.4
Wireshark ≫ Wireshark Version 1.6.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.732
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:N/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078770.html
http://secunia.com/advisories/48548
http://www.openwall.com/lists/oss-security/2012/03/28/13
http://www.securitytracker.com/id?1026874
http://anonsvn.wireshark.org/viewvc?view=revision&revision=40967
Exploit
http://www.securityfocus.com/bid/52738
http://www.wireshark.org/security/wnpa-sec-2012-05.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6809
https://exchange.xforce.ibmcloud.com/vulnerabilities/74362
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15244