3.3
CVSSv2

CVE-2012-2393

Published: 30/06/2012 Updated: 19/09/2017
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
VMScore: 335
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x prior to 1.4.13 and 1.6.x prior to 1.6.8 does not properly construct certain array data structures, which allows remote malicious users to cause a denial of service (application crash) via a crafted packet that triggers incorrect memory allocation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 1.6.0

wireshark wireshark 1.4.7

wireshark wireshark 1.4.11

wireshark wireshark 1.4.2

wireshark wireshark 1.4.0

wireshark wireshark 1.4.12

wireshark wireshark 1.4.5

wireshark wireshark 1.6.4

wireshark wireshark 1.4.13

wireshark wireshark 1.6.5

wireshark wireshark 1.4.4

wireshark wireshark 1.4.10

wireshark wireshark 1.6.3

wireshark wireshark 1.4.9

wireshark wireshark 1.6.7

wireshark wireshark 1.6.1

wireshark wireshark 1.4.6

wireshark wireshark 1.6.6

wireshark wireshark 1.4.3

wireshark wireshark 1.6.2

wireshark wireshark 1.4.1

wireshark wireshark 1.4.8

Exploits

source: wwwsecurityfocuscom/bid/53652/info Wireshark is prone to a denial-of-service vulnerability because it fails to properly allocate memory Successful exploits may allow attacker to crash the affected application, denying service to legitimate users Wireshark 140 to 1412 and 160 to 167 are vulnerable PoC: githu ...