Overview
Wireshark contains a vulnerability in the XOT dissector that may cause the application to crash.
Description
Wireshark contains a vulnerability in the XOT dissector that may allow the application to allocate a large amount of memory and cause the application to crash. This vulnerability may be exploited when a remote attacker sends a specially crafted, malformed packet or by convincing the user to read a malformed packet trace file. Wireshark states that Wireshark version 0.99.3 is affected by this vulnerability. |
Impact
A remote attacker may be able to cause a denial-of-service condition. |
Solution
Update |
Workaround |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.wireshark.org/security/wnpa-sec-2006-03.html
- http://www.securityfocus.com/bid/20762
- http://secunia.com/advisories/22590
- http://secunia.com/advisories/22659/
- http://secunia.com/advisories/22672/
- http://secunia.com/advisories/22692/
- http://secunia.com/advisories/22797/
- http://secunia.com/advisories/22841/
- http://secunia.com/advisories/22929/
Acknowledgements
This vulnerability was reported in Wireshark document wnpa-sec-2006-03.
This document was written by Katie Steiner.
Other Information
CVE IDs: | CVE-2006-4805 |
Date Public: | 2006-10-27 |
Date First Published: | 2006-11-30 |
Date Last Updated: | 2006-12-20 15:37 UTC |
Document Revision: | 18 |