CVE-2012-4291Wireshark vulnerability

CWE-3998 documents7 sources
Severity
3.3LOWNVD
EPSS
1.0%
top 23.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateMay 14

Description

The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

CVSS vector

AV:A/AC:L/C:N/I:N/A:PExploitability: 6.5 | Impact: 2.9

Affected Packages4 packages

Debianwireshark/wireshark< 1.8.2-1+3
NVDwireshark/wireshark27 versions+26
NVDsun/sunos5.11
NVDopensuse/opensuse11.4, 12.1+1

Also affects: Enterprise Linux 5

🔴Vulnerability Details

3
GHSA
GHSA-32x4-wf82-frg6: The CIP dissector in Wireshark 12022-05-14
OSV
CVE-2012-4291: The CIP dissector in Wireshark 12012-08-16
CVEList
CVE-2012-4291: The CIP dissector in Wireshark 12012-08-16

📋Vendor Advisories

2
Red Hat
wireshark: DoS via excessive system resource consumption in CIP dissector (wnpa-sec-2012-20)2012-08-15
Debian
CVE-2012-4291: wireshark - The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8...2012

💬Community

2
Bugzilla
CVE-2012-4291 wireshark: DoS via excessive system resource consumption in CIP dissector (wnpa-sec-2012-20)2012-08-15
Bugzilla
CVE-2012-4285 CVE-2012-4288 CVE-2012-4289 CVE-2012-4296 CVE-2012-4291 CVE-2012-4292 CVE-2012-4293 CVE-2012-4290 CVE-2012-4297 wireshark various flaws [fedora-all]2012-08-15
CVE-2012-4291 — Wireshark vulnerability | cvebase