SB2012061106 - Buffer overflow in wireshark (Alpine package)
Published: June 11, 2012
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2012-2393)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers incorrect memory allocation.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=67bcf52b0131b59b4461ab5d09296c5c37c1e1b5
- https://git.alpinelinux.org/aports/commit/?id=75ec09fd8cd4f2b45805710926ec9055fe2aaca2
- https://git.alpinelinux.org/aports/commit/?id=81fafbff3d179b0036765ee463d33a6c753c7f67
- https://git.alpinelinux.org/aports/commit/?id=1ad9b0fb8b0185e4b33952ae8315f64a7848cb69