wnpa-sec-2009-09 · Multiple vulnerabilities in Wireshark
Name: Multiple vulnerabilities in Wireshark
Date: December 17, 2009
Affected versions: 0.9.0 up to and including 1.2.4
Fixed versions: 1.2.5
Wireshark 1.2.5 fixes the following vulnerabilities:
The Daintree SNA file parser could overflow a buffer.
Versions affected: 1.2.0 to 1.2.4 CVE-2009-4376
The SMB and SMB2 dissectors could crash.
Versions affected: 0.9.0 to 1.2.4 CVE-2009-4377
The IPMI dissector could crash on Windows.
Versions affected: 1.2.0 to 1.2.4 CVE-2009-4378
It may be possible to make Wireshark crash remotely or by convincing someone to read a malformed packet trace file.
Upgrade to Wireshark 1.2.5 or later. Due to the nature of the Daintree SNA vulnerability, there is no workaround.