header-logo
Suggest Exploit
vendor:
Wireshark
by:
SecurityFocus
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Wireshark
Affected Version From: 1.2.0
Affected Version To: 1.4.1
Patch Exists: YES
Related CWE: N/A
CPE: a:wireshark:wireshark
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Wireshark Buffer Overflow Vulnerability

Wireshark is prone to a buffer-overflow vulnerability. Exploiting this issue may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.

Mitigation:

Upgrade to the latest version of Wireshark.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/44987/info

Wireshark is prone to a buffer-overflow vulnerability.

Exploiting this issue may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.

This issue affects Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1.

PoC: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/15676-pcap.zip