vendor:
Wireshark
by:
Google Security Research
7.5
CVSS
HIGH
Static Out-of-Bounds Read
126
CWE
Product Name: Wireshark
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Wireshark ASAN Build Static Out-of-Bounds Read Crash
A static out-of-bounds read vulnerability exists in Wireshark, specifically in the dissct_rsl_ipaccess_msg function in packet-rsl.c. By feeding a malformed file to tshark, an attacker can trigger a global buffer overflow, leading to a crash. The vulnerability can be observed in an ASAN build of Wireshark (current git master).
Mitigation:
Unknown