Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE) compression.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wiresharkUpgrade wireshark-gnome | Dec 1, 2016 | Jan 7, 2011 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Jan 7, 2011 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Jan 7, 2011 |
| Oracle_linux | — | Upgrade wiresharkUpgrade wireshark-gnomeUpgrade wireshark-devel | Oct 16, 2024 | Jan 7, 2011 |
| Suse | — | Upgrade libwireshark8Upgrade libwiretap7Upgrade libwsutil8Upgrade wireshark-develUpgrade libwireshark18Upgrade libwsutil7Upgrade libwireshark9Upgrade libwireshark19Upgrade libwiretap16Upgrade libwiretap6Upgrade libwscodecs1Upgrade wireshark-gtkUpgrade libwsutil16Upgrade libwsutil17Upgrade libwiretap15Upgrade wireshark-ui-qtUpgrade wireshark | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Jan 7, 2011 |
| Wireshark | — | Upgrade to Wireshark version 1.4.3Upgrade to Wireshark version 1.2.14 | Oct 4, 2017 | Jan 7, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub