Vulnerability Note VU#696896
Wireshark SSCOP dissector fails to properly handle malformed packets
OverviewWireshark contains a vulnerability in the SSCOP dissector that may cause a denial of service condition.
I. DescriptionWireshark contains a vulnerability in the Service-Specific Connection Oriented Protocol (SSCOP) dissector.
Wireshark states that:
If the SSCOP dissector has a port range configured and the SSCOP payload protocol is Q.2931, a malformed packet could make the Q.2931 dissector use up available memory. No port range is configured by default.
Wireshark states that Wireshark versions 0.7.9 - 0.99.2 are vulnerable.
Note: Ethereal has changed its name to Wireshark.
II. ImpactBy sending a malformed packet, a remote attacker may be able to cause the Q2931 dissector to exceed the available memory and cause a denial of service condition.
III. SolutionUpdate
Wireshark has released an updated product version (Wireshark 0.99.3)
.
Workaround
Wireshark provides a workaround in security document wnpa-sec-2006-02.
Systems Affected
| Vendor | Status | Date Updated |
| Wireshark | Vulnerable | 24-Oct-2006 |
References
http://www.wireshark.org/security/wnpa-sec-2006-02.html
http://www.securityfocus.com/bid/19690
http://www.frsirt.com/english/advisories/2006/3370
http://securitytracker.com/id?1016736
http://secunia.com/advisories/21597
http://secunia.com/advisories/21649
http://secunia.com/advisories/21813
http://secunia.com/advisories/21619
http://secunia.com/advisories/21682
http://secunia.com/advisories/21885
http://xforce.iss.net/xforce/xfdb/28556
http://xforce.iss.net/xforce/xfdb/28553
https://issues.rpath.com/browse/RPL-597
http://www.itu.int/rec/T-REC-Q.2931/en
Credit
This vulnerability was reported in Wireshark document wnpa-sec-2006-02.
This document was written by Katie Steiner.
Other Information
| Date Public | 08/25/2006 |
| Date First Published | 10/25/2006 01:15:55 PM |
| Date Last Updated | 10/25/2006 |
| CERT Advisory | |
| CVE-ID(s) | CVE-2006-4333 |
| NVD-ID(s) | CVE-2006-4333 |
| US-CERT Technical Alerts | |
| Metric | 0.56 |
| Document Revision | 16 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|