search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Wireshark HTTP dissector vulnerability

Vulnerability Note VU#363992

Original Release Date: 2007-01-02 | Last Revised: 2007-01-02

Overview

Wireshark contains a vulnerability in the HTTP dissector that may allow an attacker to cause a denial of service condition.

Description

Wireshark contains a vulnerability in the HTTP dissector that may allow an attacker to cause a denial of service condition. This vulnerability may be triggered when a remote attacker sends a specially crafted, malformed packet to a vulnerable Wireshark installation or by convincing the user to read a malformed packet trace file with Wireshark.

Wireshark states that Wireshark version 0.99.3 is affected.

Note: Ethereal has changed its name to Wireshark.

Impact

A remote attacker may be able to cause a denial of service condition.

Solution

Update
Wireshark has released an updated product version (Wireshark 0.99.4).

Workaround

Wireshark provides a workaround in security document wnpa-sec-2006-03.

Vendor Information

363992
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported in Wireshark Document wnpa-sec-2006-03.

This document was written by Katie Steiner.

Other Information

CVE IDs: CVE-2006-5468
Severity Metric: 11.39
Date Public: 2006-10-27
Date First Published: 2007-01-02
Date Last Updated: 2007-01-02 20:39 UTC
Document Revision: 17

Sponsored by CISA.