Overview
Wireshark contains a vulnerability in the DHCP dissector that may cause a denial-of-service condition.
Description
Wireshark for Microsoft Windows contains a vulnerability in the DHCP dissector that may cause a denial-of-service condition. This vulnerability may be exploited when the remote attacker sends a specially crafted, malformed packet or by convincing the user to read a malformed packet trace file. Wireshark states that Wireshark versions 0.7.9 up to and including 0.99.2 are vulnerable. |
Impact
A remote attacker may be able to cause a denial-of-service condition. |
Solution
Update |
Workaround |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.wireshark.org/security/wnpa-sec-2006-02.html
- http://www.frsirt.com/english/advisories/2006/3370
- http://securitytracker.com/id?1016736
- http://secunia.com/advisories/21597
- http://secunia.com/advisories/21649
- http://secunia.com/advisories/21619
- http://secunia.com/advisories/21682
- http://xforce.iss.net/xforce/xfdb/28554
- http://xforce.iss.net/xforce/xfdb/28553
Acknowledgements
This vulnerability was reported in Wireshark document wnpa-sec-2006-02.
This document was written by Katie Steiner.
Other Information
CVE IDs: | CVE-2006-4332 |
Severity Metric: | 3.04 |
Date Public: | 2006-08-25 |
Date First Published: | 2006-10-12 |
Date Last Updated: | 2006-10-25 17:12 UTC |
Document Revision: | 15 |