wnpa-sec-2012-06 · Wireshark pcap and pcap-ng file format crash

Summary

Name: Wireshark pcap and pcap-ng file format crash

Docid: wnpa-sec-2012-06

Date: March 27, 2012

Affected versions: 1.4.0 to 1.4.11, 1.6.0 to 1.6.5

Fixed versions: 1.4.12, 1.6.6

References: Wireshark bug 6804

Details

Description

The pcap and pcap-ng file parsers could crash trying to read ERF data.

Impact

It may be possible to make Wireshark crash convincing someone to read a malformed packet trace file.

Resolution

Upgrade to Wireshark 1.4.12, 1.6.6 or later.