Wireshark 1.8.5代码审计

通过爬取wireshark的漏洞公告页面,筛选1.8.6修复的漏洞可以得到如下结果:

1.8.6/1.8.7修复的漏洞

  • wnpa-sec-2013-31. ETCH dissector large loop. Fixed in 1.8.7.

    The ETCH dissector could go into a large loop. Discovered by Moshe Kaplan.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-30. MySQL dissector infinite loop. Fixed in 1.8.7.

    The MySQL dissector could go into an infinite loop. Discovered by Moshe Kaplan.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-29. Websocket dissector crash. Fixed in 1.8.7.

    The Websocket dissector could crash. Discovered by Moshe Kaplan.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-28. MPEG DSM-CC dissector crash. Fixed in 1.8.7.

    The MPEG DSM-CC dissector could crash.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-27. DCP ETSI dissector crash. Fixed in 1.8.7.

    The DCP ETSI dissector could crash. Discovered by Evan Jensen.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-26. PPP CCP dissector crash. Fixed in 1.8.7.

    The PPP CCP dissector could crash.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-25. ASN.1 BER dissector crash. Fixed in 1.8.7, 1.6.15.

    The ASN.1 BER dissector could crash.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-24. GTPv2 dissector crash. Fixed in 1.8.7.

    The GTPv2 dissector could crash.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-23. RELOAD dissector infinite loop. Fixed in 1.8.7.

    The RELOAD dissector could go into an infinite loop. Discovered by Evan Jensen.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-22. DTLS dissector crash. Fixed in 1.8.6, 1.6.14.

    The DTLS dissector could crash. Discovered by Laurent Butti.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-21. RELOAD dissector infinite loop. Fixed in 1.8.6.

    The RELOAD dissector could go into an infinite loop. Discovered by Even Jensen.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-20. FCSP dissector infinite loop. Fixed in 1.8.6, 1.6.14.

    The FCSP dissector could go into an infinite loop. Discovered by Moshe Kaplan.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-19. CIMD dissector crash. Fixed in 1.8.6, 1.6.14.

    The CIMD dissector could crash. Discovered by Moshe Kaplan.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-18. ACN dissector divide by zero. Fixed in 1.8.6, 1.6.14.

    The ACN dissector could attempt to divide by zero. Discovered by Alyssa Milburn.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-17. AMPQ dissector infinite loop. Fixed in 1.8.6, 1.6.14.

    The AMPQ dissector could go into an infinite loop. Discovered by Moshe Kaplan.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-16. Mount dissector crash. Fixed in 1.8.6, 1.6.14.

    The Mount dissector could crash. Discovered by Alyssa Milburn.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-15. RTPS and RTPS2 dissector crash. Fixed in 1.8.6, 1.6.14.

    The RTPS and RTPS2 dissectors could crash. Discovered by Alyssa Milburn.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-14. MPLS Echo dissector infinite loop. Fixed in 1.8.6.

    The MPLS Echo dissector could go into an infinite loop. Discovered by Laurent Butti.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-13. MS-MMS dissector crash. Fixed in 1.8.6, 1.6.14.

    The MS-MMS dissector could crash. Discovered by Laurent Butti.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-12. CSN.1 dissector crash. Fixed in 1.8.6.

    The CSN.1 dissector could crash. Discovered by Laurent Butti.It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-11. HART/IP dissector infinite loop. Fixed in 1.8.6.

    The HART/IP dissectory could go into an infinite loop.It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • wnpa-sec-2013-10. TCP dissector crash. Fixed in 1.8.6.

    The TCP dissector could crashIt may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Created att 2022-09-08T18:13:59+08:00

创建于:Thursday, September 8,2022
最后修改于: Sunday, April 30,2023