Description
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-phc2-gwgf-vq7r: The lanalyzer_read function in wiretap/lanalyzer↗2022-05-04 ▶ KernelKVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)↗2012-11-06 ▶ OSVCVE-2012-0068: The lanalyzer_read function in wiretap/lanalyzer↗2012-04-11 ▶ 📋Vendor Advisories
2Red HatWireshark: Heap-buffer underflow when parsing LANalyzer packet capture files↗2012-01-10 ▶ DebianCVE-2012-0068: wireshark - The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4...↗2012 ▶ 💬Community
2BugzillaCVE-2012-0068 Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files↗2012-01-20 ▶ BugzillaCVE-2012-0041 CVE-2012-0042 CVE-2012-0043 CVE-2012-0066 CVE-2012-0067 CVE-2012-0068 wireshark various flaws [fedora-all]↗2012-01-13 ▶