Wireshark - LDSS Dissector Buffer Overflow
Author: Nephi Johnson
type: dos
platform: multiple
port:
date_added: 2010-12-04
date_updated: 2016-11-12
verified: 1
codes: CVE-2010-4300;OSVDB-69354
tags:
aliases:
screenshot_url: http://www.exploit-db.com/screenshots/idlt16000/screen-shot-2010-12-04-at-71419-am.png
application_url:
source: https://www.securityfocus.com/bid/44987/info
Wireshark is prone to a buffer-overflow vulnerability.
Exploiting this issue may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.
This issue affects Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1.
PoC: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/15676-pcap.zip