blogs.sun.comConfirmation
http://blogs.sun.com/security/entry/buffer_overflow_vulnerability_in_wireshark CVE-2010-4300
Wireshark - LDSS Dissector Buffer Overflow
Record summary
CVE-2010-4300 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWireshark - LDSS Dissector Buffer OverflowExploitDB exploitby Nephi JohnsonNot analyzed1 file
References
Showing 12 of 24SUSE-SR:2011:001Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html SUSE-SR:2011:002Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html 69354vdb entry
http://osvdb.org/69354 42290Third-party advisory
http://secunia.com/advisories/42290 42411Third-party advisory
http://secunia.com/advisories/42411 42877Third-party advisory
http://secunia.com/advisories/42877 43068Third-party advisory
http://secunia.com/advisories/43068 15676exploit
http://www.exploit-db.com/exploits/15676 MDVSA-2010:242Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:242 RHSA-2010:0924Vendor advisory
http://www.redhat.com/support/errata/RHSA-2010-0924.html 44987vdb entry
http://www.securityfocus.com/bid/44987