Wireshark - 'call_dissector()' Null Pointer Dereference Denial of Service



EKU-ID: 24457 CVE: CVE-2012-1593;OSVDB-80711 OSVDB-ID:
Author: Wireshark Published: 2012-04-19 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/52735/info

Wireshark is prone to a remote denial-of-service vulnerability caused by a NULL-pointer-dereference error.

An attacker can exploit this issue to crash the application, resulting in a denial-of-service condition.

The following Wireshark versions are vulnerable:

1.4.0 through 1.4.11
1.6.0 through 1.6.5

PoC: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/18758.pcap