Summary
This host is installed with Wireshark
and is prone to denial of service vulnerability.
Impact
Successful exploitation will allow
attacker to cause denial of service attack
- via a crafted packet to the RTP dissector.
- via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors.
Impact Level: Application
Solution
Upgrade to Wireshark 1.10.10 or later,
For updates refer to https://www.wireshark.org
Insight
Flaws exists due to,
- the SDP dissector creates duplicate hashtables for a media channel.
- the Use-after-free vulnerability in the SDP dissector.
Affected
Wireshark version 1.10.x before 1.10.10 on Mac OS X
Detection
Get the installed version with the
help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-6421, CVE-2014-6422 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities