Lucene search

K
cveMitreCVE-2012-4292
HistoryAug 16, 2012 - 10:38 a.m.

CVE-2012-4292

2012-08-1610:38:08
CWE-20
mitre
web.nvd.nist.gov
46
wireshark
stun
dissector
denial of service
cve-2012-4292

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.003

Percentile

69.3%

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

Affected configurations

Nvd
Node
wiresharkwiresharkMatch1.6.0
OR
wiresharkwiresharkMatch1.6.1
OR
wiresharkwiresharkMatch1.6.2
OR
wiresharkwiresharkMatch1.6.3
OR
wiresharkwiresharkMatch1.6.4
OR
wiresharkwiresharkMatch1.6.5
OR
wiresharkwiresharkMatch1.6.6
OR
wiresharkwiresharkMatch1.6.7
OR
wiresharkwiresharkMatch1.6.8
OR
wiresharkwiresharkMatch1.6.9
Node
opensuseopensuseMatch11.4
OR
opensuseopensuseMatch12.1
OR
sunsunosMatch5.11
Node
wiresharkwiresharkMatch1.8.0
OR
wiresharkwiresharkMatch1.8.1
Node
wiresharkwiresharkMatch1.4.0
OR
wiresharkwiresharkMatch1.4.1
OR
wiresharkwiresharkMatch1.4.2
OR
wiresharkwiresharkMatch1.4.3
OR
wiresharkwiresharkMatch1.4.4
OR
wiresharkwiresharkMatch1.4.5
OR
wiresharkwiresharkMatch1.4.6
OR
wiresharkwiresharkMatch1.4.7
OR
wiresharkwiresharkMatch1.4.8
OR
wiresharkwiresharkMatch1.4.9
OR
wiresharkwiresharkMatch1.4.10
OR
wiresharkwiresharkMatch1.4.11
OR
wiresharkwiresharkMatch1.4.12
OR
wiresharkwiresharkMatch1.4.13
OR
wiresharkwiresharkMatch1.4.14
VendorProductVersionCPE
wiresharkwireshark1.6.5cpe:/a:wireshark:wireshark:1.6.5:::
wiresharkwireshark1.6.4cpe:/a:wireshark:wireshark:1.6.4:::
wiresharkwireshark1.6.0cpe:/a:wireshark:wireshark:1.6.0:::
wiresharkwireshark1.6.1cpe:/a:wireshark:wireshark:1.6.1:::
wiresharkwireshark1.6.6cpe:/a:wireshark:wireshark:1.6.6:::
wiresharkwireshark1.6.9cpe:/a:wireshark:wireshark:1.6.9:::
wiresharkwireshark1.6.7cpe:/a:wireshark:wireshark:1.6.7:::
wiresharkwireshark1.6.8cpe:/a:wireshark:wireshark:1.6.8:::
wiresharkwireshark1.6.2cpe:/a:wireshark:wireshark:1.6.2:::
wiresharkwireshark1.6.3cpe:/a:wireshark:wireshark:1.6.3:::

References

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.003

Percentile

69.3%