The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wireshark-develUpgrade wiresharkUpgrade wireshark-gnome | Dec 1, 2016 | Jul 7, 2011 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Jul 7, 2011 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Jul 7, 2011 |
| Oracle_linux | — | Upgrade wireshark-gnomeUpgrade wiresharkUpgrade wireshark-devel | Oct 16, 2024 | Jul 7, 2011 |
| Suse | — | Upgrade libwireshark8Upgrade wireshark-ui-qtUpgrade libwscodecs1Upgrade libwiretap15Upgrade libwiretap6Upgrade libwsutil7Upgrade libwireshark9Upgrade libwireshark19Upgrade libwireshark18Upgrade wiresharkUpgrade libwsutil8Upgrade wireshark-gtkUpgrade libwiretap7Upgrade libwiretap16Upgrade libwsutil17Upgrade libwsutil16Upgrade wireshark-devel | Feb 17, 2015 | Jun 28, 2013 |
| Wireshark | — | Upgrade to Wireshark version 1.6.1Upgrade to Wireshark version 1.4.8Upgrade to Wireshark version 1.2.18 | Oct 4, 2017 | Jul 7, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub