SB2012043003 - Amazon Linux AMI update for wireshark



SB2012043003 - Amazon Linux AMI update for wireshark

Published: April 30, 2012 Updated: March 24, 2022

Security Bulletin ID SB2012043003
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2011-1143)

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.


2) Resource management error (CVE-ID: CVE-2011-1590)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.


Remediation

Install update from vendor's website.