wnpa-sec-2009-09 · Multiple vulnerabilities in Wireshark
Summary
Name: Multiple vulnerabilities in Wireshark
Docid: wnpa-sec-2009-09
Date: December 17, 2009
Affected versions: 0.9.0 up to and including 1.2.4
Fixed versions: 1.2.5
Details
Description
Wireshark 1.2.5 fixes the following vulnerabilities:
-
The Daintree SNA file parser could overflow a buffer.
(Bug
4294)
Versions affected: 1.2.0 to 1.2.4 CVE-2009-4376 -
The SMB and SMB2 dissectors could crash.
(Bug
4301)
Versions affected: 0.9.0 to 1.2.4 CVE-2009-4377 -
The IPMI dissector could crash on Windows.
(Bug
4319)
Versions affected: 1.2.0 to 1.2.4 CVE-2009-4378
Impact
It may be possible to make Wireshark crash remotely or by convincing someone to read a malformed packet trace file.
Resolution
Upgrade to Wireshark 1.2.5 or later. Due to the nature of the Daintree SNA vulnerability, there is no workaround.