CVE-2015-0564 – wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
https://notcve.org/view.php?id=CVE-2015-0564
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session. Desbordamiento de buffer en la función ssl_decrypt_record en epan/dissectors/packet-ssl-utils.c en Wireshark 1.10.x anterior a 1.10.12 y 1.12.x anterior a 1.12.3 permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado que se maneja incorrectamente durante la descifrado de una sesión SSL. • http://advisories.mageia.org/MGASA-2015-0019.html http://lists.opensuse.org/opensuse-updates/2015-01/msg00053.html http://rhn.redhat.com/errata/RHSA-2015-1460.html http://secunia.com/advisories/62612 http://secunia.com/advisories/62673 http://www.debian.org/security/2015/dsa-3141 http://www.mandriva.com/security/advisories?name=MDVSA-2015:022 http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015- • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-131: Incorrect Calculation of Buffer Size •
CVE-2014-8712 – wireshark: NCP dissector crashes (wnpa-sec-2014-22)
https://notcve.org/view.php?id=CVE-2014-8712
The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función build_expert_data en epan/dissectors/packet-ncp2222.inc en el diseccionador NCP en Wireshark 1.10.x anterior a 1.10.11 y 1.12.x anterior a 1.12.2 no inicializa debidamente una estructura de datos, lo que permite a atacantes remotos causar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html http://lists.opensuse.org/opensuse-updates/2014-11/msg00104.html http://rhn.redhat.com/errata/RHSA-2015-1460.html http://secunia.com/advisories/60231 http://secunia.com/advisories/60290 http://www.debian.org/security/2014/dsa-3076 http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html http://www.securityfocus. • CWE-399: Resource Management Errors •
CVE-2014-8714 – wireshark: TN5250 infinite loop (wnpa-sec-2014-23)
https://notcve.org/view.php?id=CVE-2014-8714
The dissect_write_structured_field function in epan/dissectors/packet-tn5250.c in the TN5250 dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. La función dissect_write_structured_field en epan/dissectors/packet-tn5250.c en el diseccionador TN5250 en Wireshark 1.10.x anterior a 1.10.11 y 1.12.x anterior a 1.12.2 permite a atacantes remotos causar una denegación de servicio (bucle infinito) a través de un paquete manipulado. • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html http://lists.opensuse.org/opensuse-updates/2014-11/msg00104.html http://rhn.redhat.com/errata/RHSA-2015-1460.html http://secunia.com/advisories/60231 http://secunia.com/advisories/60290 http://www.debian.org/security/2014/dsa-3076 http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html http://www.oracle.com/techne • CWE-399: Resource Management Errors CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •
CVE-2014-8713 – wireshark: NCP dissector crashes (wnpa-sec-2014-22)
https://notcve.org/view.php?id=CVE-2014-8713
Stack-based buffer overflow in the build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet. Desbordamiento de buffer basado en pila en la función build_expert_data en epan/dissectors/packet-ncp2222.inc en el diseccionador NCP en Wireshark 1.10.x anterior a 1.10.11 y 1.12.x anterior a 1.12.2 permite a atacantes remotos causar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html http://lists.opensuse.org/opensuse-updates/2014-11/msg00104.html http://rhn.redhat.com/errata/RHSA-2015-1460.html http://secunia.com/advisories/60231 http://secunia.com/advisories/60290 http://www.debian.org/security/2014/dsa-3076 http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html http://www.oracle.com/techne • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-8711 – wireshark: AMQP dissector crash (wnpa-sec-2014-21)
https://notcve.org/view.php?id=CVE-2014-8711
Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet. Múltiples desbordamientos de enteros en epan/dissectors/packet-amqp.c en el diseccionador AMQP en Wireshark 1.10.x anterior a 1.10.11 y 1.12.x anterior a 1.12.2 permiten a atacantes remotos causar una denegación de servicio (caída de aplicación) a través de una PDU amqp_0_10 manipulada en un paquete. • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html http://lists.opensuse.org/opensuse-updates/2014-11/msg00104.html http://rhn.redhat.com/errata/RHSA-2015-1460.html http://secunia.com/advisories/60231 http://secunia.com/advisories/60290 http://www.debian.org/security/2014/dsa-3076 http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html http://www.securityfocus. • CWE-189: Numeric Errors •