Back to search
CVE-2012-4288
Published: Aug 16, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop or application crash) via a large value for a span length.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
55035
vdb-entry
x_refsource_BID
http://www.wireshark.org/security/wnpa-sec-2012-15.html
x_refsource_CONFIRM
54425
third-party-advisory
x_refsource_SECUNIA
GLSA-201308-05
vendor-advisory
x_refsource_GENTOO
oval:org.mitre.oval:def:15789
vdb-entry
signature
x_refsource_OVAL
51363
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2012:1035
vendor-advisory
x_refsource_SUSE
http://anonsvn.wireshark.org/viewvc?view=revision&revision=44289
x_refsource_CONFIRM
50276
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2012:1067
vendor-advisory
x_refsource_SUSE
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7571
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now