CVE-2012-0068
published 2012-04-11CVE-2012-0068: The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.60%
73.3th percentile
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.6.5-1 (bookworm) | wireshark 1.6.5-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.6.5-1 | 1.6.5-1 |
| wireshark | wireshark | >= 0 < 1.6.5-1 | 1.6.5-1 |
| wireshark | wireshark | >= 0 < 1.6.5-1 | 1.6.5-1 |
| wireshark | wireshark | >= 0 < 1.6.5-1 | 1.6.5-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phc2-gwgf-vq7r: The lanalyzer_read function in wiretap/lanalyzer
ghsa_unreviewed·2022-05-04
CVE-2012-0068 [MEDIUM] CWE-20 GHSA-phc2-gwgf-vq7r: The lanalyzer_read function in wiretap/lanalyzer
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.
Kernel
KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)
kernel_security·2012-11-06·CVSS 1.9
CVE-2012-4461 [LOW] KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)
KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)
On hosts without the XSAVE support unprivileged local user can trigger
oops similar to the one below by setting X86_CR4_OSXSAVE bit in guest
cr4 register using KVM_SET_SREGS ioctl and later issuing KVM_RUN
ioctl.
invalid opcode: 0000 [#2] SMP
Modules linked in: tun ip6table_filter ip6_tables ebtable_nat ebtables
...
Pid: 24935, comm: zoog_kvm_monito Tainted: G D 3.2.0-3-686-pae
EIP: 0060:[] EFLAGS: 00210246 CPU: 0
EIP is at kvm_arch_vcpu_ioctl_run+0x92a/0xd13 [kvm]
EAX: 00000001 EBX: 000f387e ECX: 00000000 EDX: 00000000
ESI: 00000000 EDI: 00000000 EBP: ef5a0060 ESP: d7c63e70
DS: 007b ES: 007b FS: 00d8 GS: 00e0 SS: 0068
Process zoog_kvm_monito (pid: 24935, ti=d7c62000 task=ed84a0c0
task.ti=d7c62000)
Stack:
000
OSV
CVE-2012-0068: The lanalyzer_read function in wiretap/lanalyzer
osv·2012-04-11·CVSS 4.3
CVE-2012-0068 [MEDIUM] CVE-2012-0068: The lanalyzer_read function in wiretap/lanalyzer
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.
Red Hat
Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files
vendor_redhat·2012-01-10·CVSS 4.3
CVE-2012-0068 [MEDIUM] Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files
Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.
Statement: Not vulnerable. This issue did not affect the versions of wireshark as shipped
with Red Hat Enterprise Linux 4, 5, and 6.
Package: wireshark (Red Hat Enterprise Linux 4) - Not affected
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-0068: wireshark - The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4...
vendor_debian·2012·CVSS 4.3
CVE-2012-0068 [MEDIUM] CVE-2012-0068: wireshark - The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4...
The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.
Scope: local
bookworm: resolved (fixed in 1.6.5-1)
bullseye: resolved (fixed in 1.6.5-1)
forky: resolved (fixed in 1.6.5-1)
sid: resolved (fixed in 1.6.5-1)
trixie: resolved (fixed in 1.6.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0068 Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files
bugzilla·2012-01-20·CVSS 4.3
CVE-2012-0068 [MEDIUM] CVE-2012-0068 Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files
CVE-2012-0068 Wireshark: Heap-buffer underflow when parsing LANalyzer packet capture files
A heap-based buffer underflow issue was found in way wireshark parsed LANalyzer packet capture files. It may be possible to make Wireshark crash or possibly execute arbitrary code (with the persmisisons of the user running wireshark) by convincing someone to read a malformed
IPTrace packet capture file. This is corrected in upstream 1.4.11 and 1.6.5.
Reference:
http://www.wireshark.org/security/wnpa-sec-2012-01.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6670
Patch:
http://anonsvn.wireshark.org/viewvc?view=revision&revision=40169
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of wireshark as shipped
with Red Hat Enterprise Linux 4, 5, and 6.
---
Thi
Bugzilla
CVE-2012-0041 CVE-2012-0042 CVE-2012-0043 CVE-2012-0066 CVE-2012-0067 CVE-2012-0068 wireshark various flaws [fedora-all]
bugzilla·2012-01-13·CVSS 4.3
CVE-2012-0041 [MEDIUM] CVE-2012-0041 CVE-2012-0042 CVE-2012-0043 CVE-2012-0066 CVE-2012-0067 CVE-2012-0068 wireshark various flaws [fedora-all]
CVE-2012-0041 CVE-2012-0042 CVE-2012-0043 CVE-2012-0066 CVE-2012-0067 CVE-2012-0068 wireshark various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.
http://anonsvn.wireshark.org/viewvc?view=revision&revision=40169http://secunia.com/advisories/47494http://secunia.com/advisories/54425http://www.gentoo.org/security/en/glsa/glsa-201308-05.xmlhttp://www.openwall.com/lists/oss-security/2012/01/11/7http://www.openwall.com/lists/oss-security/2012/01/20/4http://www.wireshark.org/security/wnpa-sec-2012-01.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15379http://anonsvn.wireshark.org/viewvc?view=revision&revision=40169http://secunia.com/advisories/47494http://secunia.com/advisories/54425http://www.gentoo.org/security/en/glsa/glsa-201308-05.xmlhttp://www.openwall.com/lists/oss-security/2012/01/11/7http://www.openwall.com/lists/oss-security/2012/01/20/4http://www.wireshark.org/security/wnpa-sec-2012-01.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15379
2012-04-11
Published