CVE-2012-4298
MEDIUM severity · CVSS 5.4 · CWE-189
5.4CVSS MEDIUM
Summary
Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to execute arbitrary code via a crafted packet-trace file that triggers a buffer overflow.
Impact & exploitability
Attack vectorAdjacent
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)6%
AV:A/AC:M/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://anonsvn.wireshark.org/viewvc/trunk/wiretap/vwr.c?r1=44075&r2=44074&pathrev=44075 ↗
Additional information
- NVD record
- http://anonsvn.wireshark.org/viewvc/trunk/wiretap/vwr.c?r1=44075&r2=44074&pathrev=44075Patch
- http://www.wireshark.org/security/wnpa-sec-2012-25.htmlAdvisory
- http://anonsvn.wireshark.org/viewvc?revision=44075&view=revision
- http://secunia.com/advisories/50276
- http://secunia.com/advisories/51363
- http://secunia.com/advisories/54425
- http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml
- http://www.securityfocus.com/bid/55035