Total vulnerabilities in the database
The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Software | From | Fixed in |
---|---|---|
wireshark / wireshark | 1.10.6 | 1.10.6.x |
wireshark / wireshark | 1.10.0 | 1.10.0.x |
wireshark / wireshark | 1.10.3 | 1.10.3.x |
wireshark / wireshark | 1.10.2 | 1.10.2.x |
wireshark / wireshark | 1.10.1 | 1.10.1.x |
wireshark / wireshark | 1.10.7 | 1.10.7.x |
wireshark / wireshark | 1.10.4 | 1.10.4.x |
wireshark / wireshark | 1.10.5 | 1.10.5.x |