vendor:
Wireshark
by:
Chris Benedict, Aurelien Delaitre, NIST SAMATE Project
7,5
CVSS
HIGH
Infinite Loop
835
CWE
Product Name: Wireshark
Affected Version From: 1.12.x
Affected Version To: 2.0.x
Patch Exists: YES
Related CWE: N/A
CPE: a:wireshark:wireshark:2.0.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2016
Sample generated with AFL
This infinite loop is caused by an offset of 0 being returned by wkh_content_disposition(). This offset of 0 prevents the while loop using "offset < tvb_len" from returning and results in an infinite loop.
Mitigation:
Upgrade to the latest version of TShark (Wireshark) 2.0.4