Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple Wireshark sniffer security vulnerabilities
Published:01.02.2007
Source:WIRESHARK
SecurityVulns ID:7142
Type:remote
Level:5/10
Description:Problems with Ethernet frames parsing, HTTP and LLT packets parsing.
CVE:CVE-2007-0459 (packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.)
 CVE-2007-0458 (Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.)
 CVE-2007-0457 (Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.)
 CVE-2007-0456 (Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.)
Original documentdocumentWIRESHARK, Wireshark: wnpa-sec-2007-01 (01.02.2007)
Discuss:Read or add your comments to this news (2 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru