CVE-2014-8710 – wireshark: SigComp dissector crash (wnpa-sec-2014-20)
https://notcve.org/view.php?id=CVE-2014-8710
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet. La función decompress_sigcomp_message en epan/sigcomp-udvm.c en el diseccionador SigComp UDVM en Wireshark 1.10.x anterior a 1.10.11 permite a atacantes remotos causar una denegación de servicio (sobrelectura de buffer y caída de aplicación) a través de un paquete manipulado. • http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145658.html http://lists.opensuse.org/opensuse-updates/2014-11/msg00104.html http://rhn.redhat.com/errata/RHSA-2015-1460.html http://secunia.com/advisories/60231 http://secunia.com/advisories/60290 http://www.debian.org/security/2014/dsa-3076 http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html http://www.securityfocus. • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-6424 – wireshark: Netflow dissector crash (wnpa-sec-2014-14)
https://notcve.org/view.php?id=CVE-2014-6424
The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized memory read and application crash) via a crafted packet. La función dissect_v9_v10_pdu_data en epan/dissectors/packet-netflow.c en el diseccionador Netflow en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 hace referencia a desplazamiento y variables de inicialización incorrectos, lo que permite a atacantes remotos causar una denegación de servicio (lectura de memoria no inicializada y caída de la aplicación) a través de un paquete malintencionado. • http://linux.oracle.com/errata/ELSA-2014-1676 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://www.debian.org/security/2014/dsa-3049 http://www.wireshark.org/security/wnpa-sec-2014-14.html https://bugs.wireshark.org/bugzill • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-6428 – wireshark: SES dissector crash (wnpa-sec-2014-18)
https://notcve.org/view.php?id=CVE-2014-6428
The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_spdu en epan/dissectors/packet-ses.c en el diseccionador SES en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 no inicializa adecuadamente ciertos valores ID, lo que permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de paquetes manipulados. • http://linux.oracle.com/errata/ELSA-2014-1676 http://linux.oracle.com/errata/ELSA-2014-1677 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://rhn.redhat.com/errata/RHSA-2014-1677.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://secunia.com/advisories/61933 http • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-456: Missing Initialization of a Variable •
CVE-2014-6421 – wireshark: RTP dissector crash (wnpa-sec-2014-12)
https://notcve.org/view.php?id=CVE-2014-6421
Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (application crash) via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors. Vulnerabilidad de uso después de liberación en el diseccionador SDP en Wireshark 1.10.x anterior a 1.10.10 permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado que aprovecha la titularidad de la memoría dividida entre el diseccionador SDP y RTP. • http://linux.oracle.com/errata/ELSA-2014-1676 http://linux.oracle.com/errata/ELSA-2014-1677 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://rhn.redhat.com/errata/RHSA-2014-1677.html http://secunia.com/advisories/60280 http://secunia.com/advisories/61929 http://secunia.com/advisories/61933 http://www.wireshark.org/security/wnpa • CWE-416: Use After Free •
CVE-2014-6427 – wireshark: RTSP dissector crash (wnpa-sec-2014-17)
https://notcve.org/view.php?id=CVE-2014-6427
Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers parsing of a token located one position beyond the current position. Error de superación de límite (off-by-one) en la función is_rtsp_request_or_reply en epan/dissectors/packet-rtsp.c en el diseccionador RTSP en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado que provoca analizar un token localizado una posición más allá de la posición actual. • http://linux.oracle.com/errata/ELSA-2014-1676 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://www.debian.org/security/2014/dsa-3049 http://www.wireshark.org/security/wnpa-sec-2014-17.html https://bugs.wireshark.org/bugzill • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •