3.3

CVE-2012-4292

Exploit
The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wireshark ≫ Wireshark Version 1.6.0
Wireshark ≫ Wireshark Version 1.6.1
Wireshark ≫ Wireshark Version 1.6.2
Wireshark ≫ Wireshark Version 1.6.3
Wireshark ≫ Wireshark Version 1.6.4
Wireshark ≫ Wireshark Version 1.6.5
Wireshark ≫ Wireshark Version 1.6.6
Wireshark ≫ Wireshark Version 1.6.7
Wireshark ≫ Wireshark Version 1.6.8
Wireshark ≫ Wireshark Version 1.6.9
Opensuse ≫ Opensuse Version 11.4
Opensuse ≫ Opensuse Version 12.1
Sun ≫ Sunos Version 5.11
Wireshark ≫ Wireshark Version 1.8.0
Wireshark ≫ Wireshark Version 1.8.1
Wireshark ≫ Wireshark Version 1.4.0
Wireshark ≫ Wireshark Version 1.4.1
Wireshark ≫ Wireshark Version 1.4.2
Wireshark ≫ Wireshark Version 1.4.3
Wireshark ≫ Wireshark Version 1.4.4
Wireshark ≫ Wireshark Version 1.4.5
Wireshark ≫ Wireshark Version 1.4.6
Wireshark ≫ Wireshark Version 1.4.7
Wireshark ≫ Wireshark Version 1.4.8
Wireshark ≫ Wireshark Version 1.4.9
Wireshark ≫ Wireshark Version 1.4.10
Wireshark ≫ Wireshark Version 1.4.11
Wireshark ≫ Wireshark Version 1.4.12
Wireshark ≫ Wireshark Version 1.4.13
Wireshark ≫ Wireshark Version 1.4.14
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.91% 0.771
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/54425
http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml
http://lists.opensuse.org/opensuse-updates/2012-08/msg00033.html
http://secunia.com/advisories/50276
http://secunia.com/advisories/51363
http://www.securityfocus.com/bid/55035
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_wireshark3
https://hermes.opensuse.org/messages/15514562
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-stun.c?r1=44366&r2=44365&pathrev=44366
Patch
http://anonsvn.wireshark.org/viewvc/trunk/epan/emem.c?r1=44380&r2=44379&pathrev=44380
Patch
http://anonsvn.wireshark.org/viewvc?view=revision&revision=44366
Patch
http://anonsvn.wireshark.org/viewvc?view=revision&revision=44380
http://www.wireshark.org/security/wnpa-sec-2012-21.html
Vendor Advisory
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7569
Exploit
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15158