Showing posts with label wireshark. Show all posts
Showing posts with label wireshark. Show all posts

Monday, July 22, 2019

Vulnerability Fixed In Wireshark

There have been fixed a security vulnerability in Wireshark, free open source program for analyzing network protocols. The vulnerability is related to ASN.1 BER and related dissectors. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Affected versions
-3.0.x versions 3.0.0-3.0.2
-2.6.x versions 2.6.0-2.6.9
-2.4.x versions 2.4.0-2.4.15

Non vulnerable version can be downloaded here.

More information in the security advisory

Wednesday, November 23, 2016

Vulnerabilities Fixed In Wireshark

There have been fixed vulnerabilities in Wireshark, free open source program for analyzing network protocols.

Vulnerable are 2.0.x versions 2.0.0-2.0.7 and 2.2.x versions 2.2.0-2.2.1

Non vulnerable version can be downloaded here.

More information can be read from the related advisories:
- wnpa-sec-2016-62
- wnpa-sec-2016-61
- wnpa-sec-2016-60
- wnpa-sec-2016-59
- wnpa-sec-2016-58

Wednesday, September 14, 2016

Vulnerabilities Fixed In Wireshark

There have been fixed vulnerabilities in Wireshark, free open source program for analyzing network protocols.

Vulnerable are 2.0.x versions 2.0.0-2.0.5

Non vulnerable version can be downloaded here.

More information can be read from the related advisories:
- wnpa-sec-2016-55
- wnpa-sec-2016-54
- wnpa-sec-2016-53
- wnpa-sec-2016-52
- wnpa-sec-2016-51
- wnpa-sec-2016-50

Tuesday, August 5, 2014

Vulnerability In Wireshark

There has been found a vulnerability in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerability an attacker may be able to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Vulnerable dissector components are: Catapult DCT2000, IrDA, RLC, ASN.1 BER. GTP- and GSM Management.

Vulnerable versions are: 1.10.0 - 1.10.8

Non vulnerable version of Wireshark 1.10.x series can be downloaded here. The latest stable version, Wireshark 1.12.0 can be downloaded here.

More information can be read from the related advisories:
- wnpa-sec-2014-08
- wnpa-sec-2014-09
- wnpa-sec-2014-10
- wnpa-sec-2014-11

Friday, April 18, 2014

Vulnerability In Wireshark

There has been found a vulnerability in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerability an attacker may be able to make Wireshark crash, hang, or execute code by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Vulnerable versions are: 1.10.0 - 1.10.3

Non vulnerable version of Wireshark can be downloaded here.

More information can be read from the related advisory.

Tuesday, July 30, 2013

New Versions Of Wireshark Released

There have been found and fixed some vulnerabilities in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerabilities protocol analyzers in Wireshark can be prevented from working.

Vulnerable versions:
- Wireshark 1.8 series from version 1.8.0 to 1.8.8
- Wireshark 1.10.0

Non vulnerable version of Wireshark can be downloaded here.

More information about the contents of new versions can be read from release notes:
1.8.9
1.10.1

ISC Diary entry about the update can be viewed here.





Wednesday, January 11, 2012

Vulnerabilities In Wireshark

There has been found three vulnerabilities in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerabilities an attacker may be able to make Wireshark crash, hang, or execute arbitrary code by injecting a series of malformed packets onto the wire or by convincing someone to read a malformed packet trace file.

Vulnerable versions are all versions prior 1.4.11 or 1.6.5.

Non vulnerable version of Wireshark can be downloaded here.

More information can be read from these advisories:
- http://www.wireshark.org/security/wnpa-sec-2012-01.html
- http://www.wireshark.org/security/wnpa-sec-2012-02.html
- http://www.wireshark.org/security/wnpa-sec-2012-03.html

Monday, August 2, 2010

Vulnerabilities In Wireshark

There has been found vulnerabilities in Wireshark, free open source program for analyzing network protocols. By exploiting the vulnerabilities an attacker may be able to make Wireshark crash, hang, or execute code by injecting a series of malformed packets onto the wire or by convincing someone to read a malformed packet trace file.

Vulnerable versions are all versions prior 1.0.15, 1.2.10 or 1.4.0rc2.

Non vulnerable version of Wireshark can be downloaded here.

More information can be read from these advisories:
http://www.wireshark.org/security/wnpa-sec-2010-07.html
http://www.wireshark.org/security/wnpa-sec-2010-08.html