wnpa-sec-2012-03 · Wireshark RLC dissector buffer overflow

Summary

Name: Wireshark RLC dissector buffer overflow

Docid: wnpa-sec-2012-03

Date: January 10, 2012

Affected versions: 1.4.0 to 1.4.10, 1.6.0 to 1.6.4

Fixed versions: 1.4.11, 1.6.5

References: Wireshark bug 6391

Details

Description

The RLC dissector could overflow a buffer.

Impact

It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Resolution

Upgrade to Wireshark 1.4.11, 1.6.5 or later.