CVE-2012-1595
published 2012-04-11CVE-2012-1595: The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.79%
76.1th percentile
The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.6.6-1 (bookworm) | wireshark 1.6.6-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.6.6-1 | 1.6.6-1 |
| wireshark | wireshark | >= 0 < 1.6.6-1 | 1.6.6-1 |
| wireshark | wireshark | >= 0 < 1.6.6-1 | 1.6.6-1 |
| wireshark | wireshark | >= 0 < 1.6.6-1 | 1.6.6-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Heap-based buffer overflow when reading ERF packets from pcap/pcap-ng trace files
vendor_redhat·2012-02-07·CVSS 4.3
CVE-2012-1595 [MEDIUM] CWE-122 wireshark: Heap-based buffer overflow when reading ERF packets from pcap/pcap-ng trace files
wireshark: Heap-based buffer overflow when reading ERF packets from pcap/pcap-ng trace files
The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-1595: wireshark - The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1....
vendor_debian·2012·CVSS 4.3
CVE-2012-1595 [MEDIUM] CVE-2012-1595: wireshark - The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1....
The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.
Scope: local
bookworm: resolved (fixed in 1.6.6-1)
bullseye: resolved (fixed in 1.6.6-1)
forky: resolved (fixed in 1.6.6-1)
sid: resolved (fixed in 1.6.6-1)
trixie: resolved (fixed in 1.6.6-1)
GHSA
GHSA-478p-hcx8-x6c2: The pcap_process_pseudo_header function in wiretap/pcap-common
ghsa_unreviewed·2022-05-14
CVE-2012-1595 [MEDIUM] GHSA-478p-hcx8-x6c2: The pcap_process_pseudo_header function in wiretap/pcap-common
The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.
OSV
CVE-2012-1595: The pcap_process_pseudo_header function in wiretap/pcap-common
osv·2012-04-11·CVSS 4.3
CVE-2012-1595 [MEDIUM] CVE-2012-1595: The pcap_process_pseudo_header function in wiretap/pcap-common
The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.
No detection rules found.
Exploit-DB
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
exploitdb·2012-10-09
CVE-2010-0188 Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
---
##
# $Id: mobilemail_libtiff.rb 15950 2012-10-09 18:31:08Z rapid7 $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
class Metasploit3 'Apple iOS MobileMail LibTIFF Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow in the version of
libtiff shipped with firmware versions 1.00, 1.01, 1.02, and
1.1.1 of the Apple iPhone. iPhones which have not had the BSD
tools installed will need to use a special payload.
},
'License' => MSF_LICENSE,
'Author' => ['hdm', 'kf'],
'Version' => '$Revision: 1595
Exploit-DB
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
exploitdb·2012-10-09
CVE-2010-0188 Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
---
##
# $Id: safari_libtiff.rb 15950 2012-10-09 18:31:08Z rapid7 $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
class Metasploit3 'Apple iOS MobileSafari LibTIFF Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow in the version of
libtiff shipped with firmware versions 1.00, 1.01, 1.02, and
1.1.1 of the Apple iPhone. iPhones which have not had the BSD
tools installed will need to use a special payload.
},
'License' => MSF_LICENSE,
'Author' => ['hdm', 'kf'],
'Version' => '$Revision: 1595
Bugzilla
CVE-2012-1595 CVE-2012-1596 wireshark various flaws [fedora-15]
bugzilla·2012-04-02·CVSS 4.3
CVE-2012-1595 [MEDIUM] CVE-2012-1595 CVE-2012-1596 wireshark various flaws [fedora-15]
CVE-2012-1595 CVE-2012-1596 wireshark various flaws [fedora-15]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=807644
Bugzilla
CVE-2012-1593 CVE-2012-1594 CVE-2012-1595 CVE-2012-1596 wireshark various flaws [fedora-16]
bugzilla·2012-04-02·CVSS 3.3
CVE-2012-1593 [LOW] CVE-2012-1593 CVE-2012-1594 CVE-2012-1595 CVE-2012-1596 wireshark various flaws [fedora-16]
CVE-2012-1593 CVE-2012-1594 CVE-2012-1595 CVE-2012-1596 wireshark various flaws [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new
Bugzilla
CVE-2012-1595 wireshark: Heap-based buffer overflow when reading ERF packets from pcap/pcap-ng trace files
bugzilla·2012-03-28·CVSS 4.3
CVE-2012-1595 [MEDIUM] CVE-2012-1595 wireshark: Heap-based buffer overflow when reading ERF packets from pcap/pcap-ng trace files
CVE-2012-1595 wireshark: Heap-based buffer overflow when reading ERF packets from pcap/pcap-ng trace files
An integer underflow, subsequently leading to request to allocate a large amount of memory was found in the way pcap and pcap-ng file parsers of Wireshark, a network traffic analyzer, processed Extension and / or Multi-Channel header information in ERF files. A remote attacker could provide a specially-crafted packet capture file (with size of full pseudoheader being greater than the packet size), which once opened by a local unsuspecting user would lead to wireshark executable abort.
Upstream bug report:
[1] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6804
Relevant upstream patch:
[2] http://anonsvn.wireshark.org/viewvc?view=revision&revision=41008
CVE Request:
[3] http:/
http://anonsvn.wireshark.org/viewvc?view=revision&revision=41008http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078769.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078770.htmlhttp://lists.opensuse.org/opensuse-updates/2012-04/msg00060.htmlhttp://secunia.com/advisories/48548http://secunia.com/advisories/48947http://secunia.com/advisories/48986http://www.openwall.com/lists/oss-security/2012/03/28/13http://www.securityfocus.com/bid/52737http://www.securitytracker.com/id?1026874http://www.wireshark.org/news/20120327.htmlhttp://www.wireshark.org/security/wnpa-sec-2012-06.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6804https://exchange.xforce.ibmcloud.com/vulnerabilities/74364https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15548http://anonsvn.wireshark.org/viewvc?view=revision&revision=41008http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078769.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078770.htmlhttp://lists.opensuse.org/opensuse-updates/2012-04/msg00060.htmlhttp://secunia.com/advisories/48548http://secunia.com/advisories/48947http://secunia.com/advisories/48986http://www.openwall.com/lists/oss-security/2012/03/28/13http://www.securityfocus.com/bid/52737http://www.securitytracker.com/id?1026874http://www.wireshark.org/news/20120327.htmlhttp://www.wireshark.org/security/wnpa-sec-2012-06.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6804https://exchange.xforce.ibmcloud.com/vulnerabilities/74364https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15548
2012-04-11
Published