Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r459-x2j5-rcvp

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

EPSS

Процентиль: 77%
0.0113
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 13 лет назад

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

redhat
почти 13 лет назад

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

nvd
почти 13 лет назад

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

debian
почти 13 лет назад

The dissect_stun_message function in epan/dissectors/packet-stun.c in ...

oracle-oval
больше 11 лет назад

ELSA-2013-1569: wireshark security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 77%
0.0113
Низкий

Дефекты

CWE-20