Page 8 of 53 results (0.007 seconds)

CVSS: 5.0EPSS: 1%CPEs: 9EXPL: 1

The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La funcionalidad APN decode en (1) epan/dissectors/packet-gtp.c y (2) epan/dissectors/packet-gsm_a_gm.c en los diseccionadores de GTP y GSM Management en Wireshark 1.10.x anterior a 1.10.9 no inicializa completemente cierto buffer, lo que permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado. • http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-08/msg00025.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://secunia.com/advisories/57593 http://www.debian.org/security/2014/dsa-3002 http://www.wireshark.org/security/wnpa-sec-2014-09.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10216 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=3fc441e7a5008640c68ec985 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 1%CPEs: 9EXPL: 1

The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función rlc_decode_li en epan/dissectors/packet-rlc.c en el diseccionados de RLC en Wireshark 1.10.x anterior a 1.10.9 inicializa cierto miembro de estructuras solamente después de que este miembro se haya utilizado, lo que permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) a través de un paquete manipulado. • http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-08/msg00025.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://secunia.com/advisories/57593 http://www.debian.org/security/2014/dsa-3002 http://www.wireshark.org/security/wnpa-sec-2014-10.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9795 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=ba6eb5c72ffe82ca0e51c7083 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 1%CPEs: 9EXPL: 1

The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet. La función dissect_ber_constrained_bitstring en epan/dissectors/packet-ber.c en el diseccionador ASN.1 BER en Wireshark 1.10.x anterior a 1.10.9 no valida debidamente los valores de relleno (padding), lo que permite a atacantes remotos causar una denegación de servicio (subdesbordamiento de buffer y caída de la aplicación) a través de un paquete manipulado. • http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00033.html http://lists.opensuse.org/opensuse-updates/2014-08/msg00025.html http://lists.opensuse.org/opensuse-updates/2014-09/msg00058.html http://secunia.com/advisories/57593 http://www.debian.org/security/2014/dsa-3002 http://www.wireshark.org/security/wnpa-sec-2014-11.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10187 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=17a552666b50896a9b9dde8e • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 4.3EPSS: 1%CPEs: 8EXPL: 2

The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_frame en epan/dissectors/packet-frame.c en el marco metadissector en Wireshark 1.10.x anterior a 1.10.8 interpreta un entero negativo como un valor de longitud aunque la intención era de representar una condición de error, lo que permite a atacantes remotos causar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://lists.opensuse.org/opensuse-updates/2014-06/msg00049.html http://www.wireshark.org/security/wnpa-sec-2014-07.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10030 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9999 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=beb119f911a698d44f4baa06d888bb1e775983bc • CWE-189: Numeric Errors •

CVSS: 9.3EPSS: 4%CPEs: 4EXPL: 2

wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet. wiretap/libpcap.c en el analizador de ficheros libpcap en Wireshark 1.10.x anterior a 1.10.4 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de aplicación) a través de un fichero de traza de paquetes manipulado que incluye un paquete grande. • http://anonsvn.wireshark.org/viewvc/trunk-1.10/wiretap/libpcap.c?r1=53123&r2=53122&pathrev=53123 http://anonsvn.wireshark.org/viewvc?view=revision&revision=53123 http://www.wireshark.org/security/wnpa-sec-2014-05.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8808 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9390 https://bugs.wireshark.org/bugzilla/show_bug.cgi? • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •