Korean
<< Back
VID 28273
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Wireshark which is older than 1.2.9 or version of Etherial which is older than 1.0.14 has been installed on the host. Wireshark is a free packet analyzer computer application. There are vulnerable to multiple vulnerabilities.

- The SMB dissector can be affected by a NULL pointer dereference. (Bug 4734)
- The ANS.1 BER dissector can be affected by a buffer overflow.
- The SMB PIPE dissector can be affected by a NULL pointer dereference on some platforms.

- The SigComp Universal Decompressor Virtual Machine can be affected by an infinite loop or a buffer overflow.(Bug 4826, 4837)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.wireshark.org/security/wnpa-sec-2010-05.html
http://www.wireshark.org/security/wnpa-sec-2010-06.html

* Platforms Affected:
Wireshark versions prior to 1.2.9 or prior to 1.0.14
Microsoft Windows Any version
Recommendation Upgrade to the latest version Wireshark (1.0.14/1.2.9 or later), available from the Wireshark.org Web site at http://www.wireshark.org/download.html
Related URL CVE-2010-2283,CVE-2010-2284,CVE-2010-2285,CVE-2010-2286,CVE-2010-2287 (CVE)
Related URL 40728 (SecurityFocus)
Related URL (ISS)