Wireshark - Multiple Dissector Denial of Service Vulnerabilities
Author: Laurent Butti
type: dos
platform: multiple
port:
date_added: 2012-05-24
date_updated: 2016-11-12
verified: 1
codes: OSVDB-82160;OSVDB-82159;OSVDB-82158;OSVDB-82157;OSVDB-82156;OSVDB-82155;OSVDB-82154;OSVDB-82098;CVE-2012-3826;CVE-2012-3825;CVE-2012-2392
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/53651/info
Wireshark is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues to crash the affected application, denying service to legitimate users.
Wireshark versions 1.6.0 through 1.6.7 and versions 1.4.0 through 1.4.12 are vulnerable.
PoC:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-1.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-2.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-3.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-4.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-5.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-6.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-7.pcap
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18919-8.pcap