
CVE-2012-4292 – wireshark: crash in STUN dissector (wnpa-sec-2012-21)
https://notcve.org/view.php?id=CVE-2012-4292
16 Aug 2012 — The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. La función dissect_stun_message en epan/dissectors/packet-stun.c en STUN dissector en Wireshark v1.4.x anterior a v1.4.15, v1.6.x anterior a v1.6.10, y v1.8.x... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-stun.c?r1=44366&r2=44365&pathrev=44366 • CWE-20: Improper Input Validation •

CVE-2012-4293 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2012-4293
16 Aug 2012 — plugins/ethercat/packet-ecatmb.c in the EtherCAT Mailbox dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly handle certain integer fields, which allows remote attackers to cause a denial of service (application exit) via a malformed packet. plugins/EtherCAT/packet-ecatmb.c en el disector de buzón de correo EtherCAT en Wireshark v1.4.x antes de v1.4.15, v1.6.x antes de v1.6.10 y v1.8.x antes de v1.8.2 no maneja adecuadamente ciertos campos enteros, lo qu... • http://anonsvn.wireshark.org/viewvc/trunk/plugins/ethercat/packet-ecatmb.c?r1=43149&r2=43148&pathrev=43149 • CWE-189: Numeric Errors •

CVE-2012-4294 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2012-4294
16 Aug 2012 — Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value. Un desbordamiento de búfer en la función channelised_fill_sdh_g707_format en epan/dissectors/packet-erf.c en el disector de ERF en Wireshark v1.8.x antes de v1.8.2 permite a atacantes remotos ejecutar código de su elección a través de un valor de velocidad (aka rate) demasiad... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-erf.c?r1=44377&r2=44376&pathrev=44377 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-4295 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2012-4295
16 Aug 2012 — Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value. Error de índice de array en la función channelised_fill_sdh_g707_format en epan/disectores/erf.c en el disector ERF en Wireshark v1.8.x antes de v1.8.2 podría permitir a atacantes remotos provocar una denegación de servicio (por caída de la apl... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-erf.c?r1=44419&r2=44418&pathrev=44419 • CWE-20: Improper Input Validation •

CVE-2012-4296 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2012-4296
16 Aug 2012 — Buffer overflow in epan/dissectors/packet-rtps2.c in the RTPS2 dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet. Un desbordamiento de búfer en epan/dissectors/packet-rtps2.c en el disector RTPS2 en Wireshark v1.4.x antes de v1.4.15, v1.6.10 antes v1.6.x, y v1.8.x antes de v1.8.2 permite a atacantes remotos provocar una denegación de servicio (por excesivo consumo de CPU) a tra... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-rtps2.c?r1=44320&r2=44319&pathrev=44320 • CWE-399: Resource Management Errors •

CVE-2012-4297 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2012-4297
16 Aug 2012 — Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in Wireshark 1.6.x before 1.6.10 and 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a malformed packet. Un desbordamiento de búfer en la función dissect_gsm_rlcmac_downlink en epan/ dissectors/packet-gsm_rlcmac.c en GSM RLC MAC dissector en Wireshark v1.6.x antes de v1.6.10 y v1.8.x antes de v1.8.2 permite a atacantes remotos ejecutar código de su elección... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-gsm_rlcmac.h?r1=44307&r2=44306&pathrev=44307 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-4298 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2012-4298
16 Aug 2012 — Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to execute arbitrary code via a crafted packet-trace file that triggers a buffer overflow. Error de signo de entero en la función vwr_read_rec_data_ethernet en wiretap/vwr.c en el analizador de archivos Ixia IxVeriWave en Wireshark v1.8.x antes de v1.8.2 permite a atacantes remotos asistidos por el usuario ejecutar códig... • http://anonsvn.wireshark.org/viewvc/trunk/wiretap/vwr.c?r1=44075&r2=44074&pathrev=44075 • CWE-189: Numeric Errors •

CVE-2012-3130
https://notcve.org/view.php?id=CVE-2012-3130
17 Jul 2012 — Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd. Vulnerabilidad no especificada en Oracle Sun Solaris v11 permite a atacantes remotos afectar a la integridad a través de vectores desconocidos relacionados con pkg.depotd. • http://osvdb.org/83931 •

CVE-2012-3131
https://notcve.org/view.php?id=CVE-2012-3131
17 Jul 2012 — Unspecified vulnerability in Oracle Sun Solaris 9, 10, and 11 allows remote attackers to affect confidentiality, related to Network/NFS. Vulnerabilidad no especificada relacionada con Network/NFS en Oracle Sun Solaris v9, v10 y v11 permite a atacantes remotos afectar la confidencialidad. • http://osvdb.org/83930 •

CVE-2012-1687
https://notcve.org/view.php?id=CVE-2012-1687
17 Jul 2012 — Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability, related to Logical Domains (LDOM). Vulnerabilidad no especificada en Oracle Solaris v10 y v11 permite a los usuarios locales a afectar a la integridad y la disponibilidad, en relación con los dominios lógicos (LDOM). • http://osvdb.org/83938 •