Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2014.0070 A vulnerability has been identified in Wireshark that affect versions prior to 1.10.8 and 1.8.15 13 June 2014 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Wireshark Operating System: UNIX variants (UNIX, Linux, OSX) Windows Impact/Access: Denial of Service -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2014-4020 Member content until: Sunday, July 13 2014 OVERVIEW A vulnerability has been identified in Wireshark that affect versions prior to 1.10.8 and 1.8.15. [1] IMPACT The vendor has provided the following details on the vulnerability: "It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file." [1] MITIGATION The vendor recommends upgrading to the latest version of Wireshark. REFERENCES [1] wnpa-sec-2014-07 · Frame metadissector crash https://www.wireshark.org/security/wnpa-sec-2014-07.html AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBU5pThxLndAQH1ShLAQIQNRAAgbkIoSnn84THg7Jr3/oaMnt8eJ84vQnu URMWiTHQxkQW7svvTM9WFjS5UatYI5WnHx7wm5eUo69iqmSbLVwlOOn7Ipva1urS wbRUFVoakyDYkqCvZsggjFGH29FE0tikWl5FJ6h4BymsYvYdIS7ihpL1rYhiMPTy PFdgVmw5wBUnZK6EFUsH9mJca/oUTAZ6h1XS9pwOdaBVqzo82VVO1CIP6YsqRVMq uYmpYzpIs3qRW/b6rxxf2bCAsdXC65lNYXnbGjTsG1Gks0R59xmmwPrzLNN22yFn ABFvWISB36eKwsj2PPkghleuigpw9ptI4OV+K/SQrDGGSjX9DBJ79vefpgjpfpMa C5hFOXy1Uamxk2ScBv1Q9RaTS40WmrrIgRn0XNfrJn5rh6LRVEAsPNZLrsC8sNak Wuk3VGyNS464A1tHcgsAGqxQ0n4LH0ZzuucngBe0uNQhEUGUGJaPakybrOqTFD/W LQJgjMZeZCjEOEIeOvk4ym26UFys/MwQG292mDJX1Sf7k9uXgqlw9jZB+ZJdawUK HbfZyICUVuLpmaiSSYehy22LlPH/TJKPFvYd2HKwRyRNQDw+G0VRGxv6Ixd+lvvW kbluNifaFn9HYy1pn7Fa8DNx12icSiAAtocSQi7uFcJVefC+r2DauD80ICoP8Hb5 /n9UXThg3YU= =XrD6 -----END PGP SIGNATURE-----