Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.805395
Kategorie:Denial of Service
Titel:Wireshark Multiple Denial-of-Service Vulnerabilities-02 June15 (Mac OS X)
Zusammenfassung:This host is installed with Wireshark; and is prone to multiple denial of service vulnerabilities.
Beschreibung:Summary:
This host is installed with Wireshark
and is prone to multiple denial of service vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- The X11 dissector that is triggered when handling a specially crafted
packet, which can result in a memory leak.

- 'epan/dissectors/packet-wcp.c' in the WCP dissector improperly refers to
previously processed bytes.

- The IEEE 802.11 dissector that is triggered when handling a malformed
packet, which can result in an infinite loop.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to conduct denial of service attack.

Affected Software/OS:
Wireshark version 1.10.x before 1.10.14
and 1.12.x before 1.12.5 on Mac OS X

Solution:
Upgrade to version 1.10.14 or 1.12.5 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Querverweis: BugTraq ID: 74637
BugTraq ID: 74635
BugTraq ID: 74631
Common Vulnerability Exposure (CVE) ID: CVE-2015-3814
http://www.securityfocus.com/bid/74631
Debian Security Information: DSA-3277 (Google Search)
http://www.debian.org/security/2015/dsa-3277
https://security.gentoo.org/glsa/201510-03
Common Vulnerability Exposure (CVE) ID: CVE-2015-3812
http://www.securityfocus.com/bid/74637
RedHat Security Advisories: RHSA-2017:0631
http://rhn.redhat.com/errata/RHSA-2017-0631.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-3811
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.