Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.805392
Categoría:Denial of Service
Título:Wireshark Multiple Denial-of-Service Vulnerabilities-01 June15 (Windows)
Resumen:This host is installed with Wireshark; and is prone to multiple denial of service vulnerabilities.
Descripción:Summary:
This host is installed with Wireshark
and is prone to multiple denial of service vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- The 'logcat_dump_text' function in 'wiretap/logcat.c' in the Android
Logcat file parser does not properly handle a lack of \0 termination.

- The 'detect_version' function in 'wiretap/logcat.c' in the Android Logcat
file parser does not check the length of the payload.

- The 'fragment_add_work' function in 'epan/reassemble.c' in the packet-reassembly
feature does not properly determine the defragmentation state in a case of an
insufficient snapshot length.

- 'epan/dissectors/packet-websocket.c' in the WebSocket dissector uses a
recursive algorithm, which can result in a consumption of CPU resources.

- The 'dissect_lbmr_pser' function in 'epan/dissectors/packet-lbmr.c' in
the LBMR dissector does not properly track the current offset and does not
reject a zero length.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to conduct denial of service attack.

Affected Software/OS:
Wireshark version 1.12.x before 1.12.5
on Windows

Solution:
Upgrade to version 1.12.5 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: BugTraq ID: 74837
BugTraq ID: 74630
BugTraq ID: 74629
BugTraq ID: 74633
BugTraq ID: 74632
BugTraq ID: 74628
Common Vulnerability Exposure (CVE) ID: CVE-2015-3906
http://www.securityfocus.com/bid/74837
https://security.gentoo.org/glsa/201510-03
Common Vulnerability Exposure (CVE) ID: CVE-2015-3815
http://www.securityfocus.com/bid/74630
Debian Security Information: DSA-3277 (Google Search)
http://www.debian.org/security/2015/dsa-3277
https://blog.fuzzing-project.org/11-Read-heap-overflow-invalid-memory-access-in-Wireshark-TFPA-0072015.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-3813
http://www.securityfocus.com/bid/74633
RedHat Security Advisories: RHSA-2017:0631
http://rhn.redhat.com/errata/RHSA-2017-0631.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-3810
http://www.securityfocus.com/bid/74629
Common Vulnerability Exposure (CVE) ID: CVE-2015-3809
http://www.securityfocus.com/bid/74632
Common Vulnerability Exposure (CVE) ID: CVE-2015-3808
http://www.securityfocus.com/bid/74628
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.