Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 8349] New: NRB Host name dislusure bug not fixed

Date: Mon, 18 Feb 2013 13:21:16 +0000
Bug ID 8349
Summary NRB Host name dislusure bug not fixed
Classification Unclassified
Product Wireshark
Version 1.8.4
Hardware x86
OS Windows Server 2003
Status UNCONFIRMED
Severity Normal
Priority Low
Component Wireshark
Assignee [email protected]
Reporter [email protected]

Build Information:
Wireshark / Dumpcap 1.8.4 (SVN Rev 46250 from /trunk-1.8)
--
PCAP-NG files contain Name Resolution Block (NRB) nres_ip6record and
nres_ip4record entries for hosts that aren't in the capture files.

Here is an example:
http://netresec.com/?b=132A297

The name resolution entries (and other metadata) in this example were extracted
by uploading the pcap-ng file to http://pcapng.com

This bug should have been corrected in version 1.8.4 if I understand the
description for wnpa-sec-2012-30 (Wireshark pcap-ng host name disclosure)
correctly.
http://www.wireshark.org/security/wnpa-sec-2012-30.html

But it seems the bug is still not properly fixed.


You are receiving this mail because:
  • You are watching all bug changes.