CVE-2014-6427 – wireshark: RTSP dissector crash (wnpa-sec-2014-17)
https://notcve.org/view.php?id=CVE-2014-6427
Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers parsing of a token located one position beyond the current position. Error de superación de límite (off-by-one) en la función is_rtsp_request_or_reply en epan/dissectors/packet-rtsp.c en el diseccionador RTSP en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado que provoca analizar un token localizado una posición más allá de la posición actual. • http://linux.oracle.com/errata/ELSA-2014-1676 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://www.debian.org/security/2014/dsa-3049 http://www.wireshark.org/security/wnpa-sec-2014-17.html https://bugs.wireshark.org/bugzill • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •
CVE-2014-6423 – wireshark: MEGACO dissector infinite loop (wnpa-sec-2014-13)
https://notcve.org/view.php?id=CVE-2014-6423
The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line. La función tvb_raw_text_add en epan/dissectors/packet-megaco.c en el diseccionador MEGACO en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 permite a atacantes remotos causar una denegación de servicio (bucle infinito) a través de una línea en blanco. • http://linux.oracle.com/errata/ELSA-2014-1676 http://linux.oracle.com/errata/ELSA-2014-1677 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://rhn.redhat.com/errata/RHSA-2014-1677.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://secunia.com/advisories/61933 http • CWE-399: Resource Management Errors CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •
CVE-2014-6432 – wireshark: DOS Sniffer file parser flaw (wnpa-sec-2014-19)
https://notcve.org/view.php?id=CVE-2014-6432
The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not prevent data overwrites during copy operations, which allows remote attackers to cause a denial of service (application crash) via a crafted file. La función SnifferDecompress en wiretap/ngsniffer.c en el analizador de ficheros DOS Sniffer en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 no previene la sobreescritura de datos durante operaciones de copia, lo que permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un fichero manipulado. • http://linux.oracle.com/errata/ELSA-2014-1676 http://linux.oracle.com/errata/ELSA-2014-1677 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://rhn.redhat.com/errata/RHSA-2014-1677.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://secunia.com/advisories/61933 http • CWE-399: Resource Management Errors •
CVE-2014-6422 – wireshark: RTP dissector crash (wnpa-sec-2014-12)
https://notcve.org/view.php?id=CVE-2014-6422
The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector. El diseccionador SDP en Wireshark 1.10.x anterior a 1.10.10 crea tablas hash duplicadas para un canal de medios, lo que permite a un atacante causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado hacia el diseccionador RTP. • http://linux.oracle.com/errata/ELSA-2014-1676 http://linux.oracle.com/errata/ELSA-2014-1677 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://rhn.redhat.com/errata/RHSA-2014-1677.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://secunia.com/advisories/61933 http • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-416: Use After Free •
CVE-2014-6431 – wireshark: DOS Sniffer file parser flaw (wnpa-sec-2014-19)
https://notcve.org/view.php?id=CVE-2014-6431
Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers writes of uncompressed bytes beyond the end of the output buffer. Desbordamiento de buffer en la función SnifferDecompress en wiretap/ngsniffer.c en el analizador de ficheros DOS Sniffer en Wireshark 1.10.x anterior a 1.10.10 y 1.12.x anterior a 1.12.1 no previene la sobreescritura de datos durante operaciones de copia, lo que permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un fichero manipulado que provoca escrituras de bytes descomprimidos más allá del final del buffer de salida. • http://linux.oracle.com/errata/ELSA-2014-1676 http://linux.oracle.com/errata/ELSA-2014-1677 http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://rhn.redhat.com/errata/RHSA-2014-1676.html http://rhn.redhat.com/errata/RHSA-2014-1677.html http://secunia.com/advisories/60280 http://secunia.com/advisories/60578 http://secunia.com/advisories/61929 http://secunia.com/advisories/61933 http • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •