Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p72-rmv7-7jc9

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS

Процентиль: 71%
0.00679
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 10 лет назад

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

redhat
около 10 лет назад

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

nvd
около 10 лет назад

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

debian
около 10 лет назад

The ptvcursor_add function in the ptvcursor implementation in epan/pro ...

suse-cvrf
почти 10 лет назад

Security update for wireshark

EPSS

Процентиль: 71%
0.00679
Низкий

Дефекты

CWE-20