There have been fixed a security vulnerability in Wireshark, free open source program for analyzing network protocols. The vulnerability is related to ASN.1 BER and related dissectors. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Affected versions
-3.0.x versions 3.0.0-3.0.2
-2.6.x versions 2.6.0-2.6.9
-2.4.x versions 2.4.0-2.4.15
Non vulnerable version can be downloaded here.
More information in the security advisory
Showing posts with label wireshark. Show all posts
Showing posts with label wireshark. Show all posts
Monday, July 22, 2019
Wednesday, November 23, 2016
Vulnerabilities Fixed In Wireshark
There have been fixed vulnerabilities in Wireshark, free open source program for analyzing network protocols.
Vulnerable are 2.0.x versions 2.0.0-2.0.7 and 2.2.x versions 2.2.0-2.2.1
Non vulnerable version can be downloaded here.
More information can be read from the related advisories:
- wnpa-sec-2016-62
- wnpa-sec-2016-61
- wnpa-sec-2016-60
- wnpa-sec-2016-59
- wnpa-sec-2016-58
Vulnerable are 2.0.x versions 2.0.0-2.0.7 and 2.2.x versions 2.2.0-2.2.1
Non vulnerable version can be downloaded here.
More information can be read from the related advisories:
- wnpa-sec-2016-62
- wnpa-sec-2016-61
- wnpa-sec-2016-60
- wnpa-sec-2016-59
- wnpa-sec-2016-58
Wednesday, September 14, 2016
Vulnerabilities Fixed In Wireshark
There have been fixed vulnerabilities in Wireshark, free open source program for analyzing network protocols.
Vulnerable are 2.0.x versions 2.0.0-2.0.5
Non vulnerable version can be downloaded here.
More information can be read from the related advisories:
- wnpa-sec-2016-55
- wnpa-sec-2016-54
- wnpa-sec-2016-53
- wnpa-sec-2016-52
- wnpa-sec-2016-51
- wnpa-sec-2016-50
Vulnerable are 2.0.x versions 2.0.0-2.0.5
Non vulnerable version can be downloaded here.
More information can be read from the related advisories:
- wnpa-sec-2016-55
- wnpa-sec-2016-54
- wnpa-sec-2016-53
- wnpa-sec-2016-52
- wnpa-sec-2016-51
- wnpa-sec-2016-50
Tuesday, August 5, 2014
Vulnerability In Wireshark
There has been found a vulnerability in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerability an attacker may be able to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Vulnerable dissector components are: Catapult DCT2000, IrDA, RLC, ASN.1 BER. GTP- and GSM Management.
Vulnerable versions are: 1.10.0 - 1.10.8
Non vulnerable version of Wireshark 1.10.x series can be downloaded here. The latest stable version, Wireshark 1.12.0 can be downloaded here.
More information can be read from the related advisories:
- wnpa-sec-2014-08
- wnpa-sec-2014-09
- wnpa-sec-2014-10
- wnpa-sec-2014-11
Vulnerable versions are: 1.10.0 - 1.10.8
Non vulnerable version of Wireshark 1.10.x series can be downloaded here. The latest stable version, Wireshark 1.12.0 can be downloaded here.
More information can be read from the related advisories:
- wnpa-sec-2014-08
- wnpa-sec-2014-09
- wnpa-sec-2014-10
- wnpa-sec-2014-11
Friday, April 18, 2014
Vulnerability In Wireshark
There has been found a vulnerability in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerability an attacker may be able to make Wireshark crash, hang, or execute code by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Vulnerable versions are: 1.10.0 - 1.10.3
Non vulnerable version of Wireshark can be downloaded here.
More information can be read from the related advisory.
Vulnerable versions are: 1.10.0 - 1.10.3
Non vulnerable version of Wireshark can be downloaded here.
More information can be read from the related advisory.
Tuesday, July 30, 2013
New Versions Of Wireshark Released
There have been found and fixed some vulnerabilities in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerabilities protocol analyzers in Wireshark can be prevented from working.
Vulnerable versions:
- Wireshark 1.8 series from version 1.8.0 to 1.8.8
- Wireshark 1.10.0
Non vulnerable version of Wireshark can be downloaded here.
More information about the contents of new versions can be read from release notes:
1.8.9
1.10.1
ISC Diary entry about the update can be viewed here.
Vulnerable versions:
- Wireshark 1.8 series from version 1.8.0 to 1.8.8
- Wireshark 1.10.0
Non vulnerable version of Wireshark can be downloaded here.
More information about the contents of new versions can be read from release notes:
1.8.9
1.10.1
ISC Diary entry about the update can be viewed here.
Wednesday, January 11, 2012
Vulnerabilities In Wireshark
There has been found three vulnerabilities in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerabilities an attacker may be able to make Wireshark crash, hang, or execute arbitrary code by injecting a series of malformed packets onto the wire or by convincing someone to read a malformed packet trace file.
Vulnerable versions are all versions prior 1.4.11 or 1.6.5.
Non vulnerable version of Wireshark can be downloaded here.
More information can be read from these advisories:
- http://www.wireshark.org/security/wnpa-sec-2012-01.html
- http://www.wireshark.org/security/wnpa-sec-2012-02.html
- http://www.wireshark.org/security/wnpa-sec-2012-03.html
Vulnerable versions are all versions prior 1.4.11 or 1.6.5.
Non vulnerable version of Wireshark can be downloaded here.
More information can be read from these advisories:
- http://www.wireshark.org/security/wnpa-sec-2012-01.html
- http://www.wireshark.org/security/wnpa-sec-2012-02.html
- http://www.wireshark.org/security/wnpa-sec-2012-03.html
Monday, August 2, 2010
Vulnerabilities In Wireshark
There has been found vulnerabilities in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerabilities an attacker may be able to make Wireshark crash, hang, or execute code by injecting a series of malformed packets onto the wire or by convincing someone to read a malformed packet trace file.
Vulnerable versions are all versions prior 1.0.15, 1.2.10 or 1.4.0rc2.
Non vulnerable version of Wireshark can be downloaded here.
More information can be read from these advisories:
http://www.wireshark.org/security/wnpa-sec-2010-07.html
http://www.wireshark.org/security/wnpa-sec-2010-08.html
Vulnerable versions are all versions prior 1.0.15, 1.2.10 or 1.4.0rc2.
Non vulnerable version of Wireshark can be downloaded here.
More information can be read from these advisories:
http://www.wireshark.org/security/wnpa-sec-2010-07.html
http://www.wireshark.org/security/wnpa-sec-2010-08.html
Subscribe to:
Posts (Atom)