Korean
<< Back
VID 28291
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Wireshark which is older than 1.2.14/1.4.3 has been installed on the host. Wireshark is a free packet analyzer computer application. The installed version of Wireshark or Ethereal is affected by multiple vulnerabilities.

- An error exists in the MAC-LTE dissector that allows a series of malformed packets to cause a buffer overflow.(5530)

- An error exists in the ENTTEC dissector that allows a series of malformed packets to cause a buffer overflow.(5539)

- An error exists in the ASN.1 BER dissector that allows a series of malformed packets to make Wireshark exit prematurely. (5537)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.wireshark.org/security/wnpa-sec-2011-01.html
http://www.wireshark.org/security/wnpa-sec-2011-02.html
http://www.wireshark.org/docs/relnotes/wireshark-1.2.14.html
http://www.wireshark.org/docs/relnotes/wireshark-1.4.3.html

* Platforms Affected:
Wireshark versions prior to 1.2.14 / 1.4.3
Microsoft Windows Any version
Recommendation Upgrade to the latest version Wireshark (1.2.14/1.4.3 or later), available from the Wireshark.org Web site at http://www.wireshark.org/download.html
Related URL CVE-2010-4538,CVE-2011-0444,CVE-2011-0445 (CVE)
Related URL 45634,45775 (SecurityFocus)
Related URL (ISS)