wnpa-sec-2009-03 · PCNFSD vulnerability in Wireshark
Summary
Name: PCNFSD vulnerability in Wireshark
Docid: wnpa-sec-2009-03
Date: May 21, 2009
Affected versions: 0.8.20 up to and including 1.0.7
Fixed versions: 1.0.8
Details
Description
Wireshark 1.0.8 fixes the following vulnerability:
- The PCNFSD dissector could crash. Versions affected: 0.8.20 to 1.0.7
Impact
It may be possible to make Wireshark crash remotely or by convincing someone to read a malformed packet trace file.
Resolution
Upgrade to Wireshark 1.0.8 or later.
If are running Wireshark {{ end_version }} or earlier (including Ethereal) and cannot upgrade, you can work around each of the problems listed above by doing the following:
- Disable the PCNFSD dissector:
- Select Analyze→Enabled Protocols... from the menu.
- Make sure "PCNFSD" is un-checked.
- Click "Save", then click "OK".