Lucene search

K
cveMitreCVE-2012-4294
HistoryAug 16, 2012 - 10:38 a.m.

CVE-2012-4294

2012-08-1610:38:08
CWE-119
mitre
web.nvd.nist.gov
29
cve-2012-4294
buffer overflow
wireshark
erf dissector
remote code execution

CVSS2

5.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.07

Percentile

94.0%

Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.

Affected configurations

Nvd
Node
wiresharkwiresharkMatch1.8.0
OR
wiresharkwiresharkMatch1.8.1
Node
sunsunosMatch5.11
VendorProductVersionCPE
wiresharkwireshark1.8.0cpe:/a:wireshark:wireshark:1.8.0:::
wiresharkwireshark1.8.1cpe:/a:wireshark:wireshark:1.8.1:::

CVSS2

5.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.07

Percentile

94.0%