HTTP: Wireshark MPEG Dissector Stack Buffer Overflow
This signature detects attempts to exploit a known vulnerability in Wireshark. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the targeted application.
Extended Description
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
Affected Products
Wireshark wireshark
References
BugTraq: 66066
CVE: CVE-2014-2299
URL: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commitdiff;h=34144b8d4da141e8aa9b99221855edc9f4c73ad8 https://code.wireshark.org/review/#/c/533/ https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9843 http://www.wireshark.org/security/wnpa-sec-2014-04.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Wireshark
9.3