Total vulnerabilities in the database
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.
Software | From | Fixed in |
---|---|---|
wireshark / wireshark | 1.10.8 | 1.10.8.x |
wireshark / wireshark | 1.10.6 | 1.10.6.x |
wireshark / wireshark | 1.10.0 | 1.10.0.x |
wireshark / wireshark | 1.10.3 | 1.10.3.x |
wireshark / wireshark | 1.10.2 | 1.10.2.x |
wireshark / wireshark | 1.10.1 | 1.10.1.x |
wireshark / wireshark | 1.10.7 | 1.10.7.x |
wireshark / wireshark | 1.10.4 | 1.10.4.x |
wireshark / wireshark | 1.10.5 | 1.10.5.x |