APP: Wireshark Dissector LWRES Buffer Overflow

This signature detects attempts to exploit a known vulnerability against Wireshark. A successful attack can lead to arbitrary code execution.

Extended Description

Wireshark is prone to multiple buffer-overflow vulnerabilities. Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application. These issues affect Wireshark 0.9.0 through 1.2.5.

Affected Products

Pardus linux_2009

Short Name
APP:WIRESHARK-LWRES
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Buffer CVE-2010-0304 Dissector LWRES Overflow Wireshark bid:37985
Release Date
05/08/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3653
Port
UDP/921
False Positive
Unknown
Vendors

Red_hat

Suse

Ethereal_group

Avaya

Pardus

Debian

Wireshark

CVSS Score

7.5

Found a potential security threat?