Candidate: CVE-2012-2392 PublicDate: 2012-06-30 10:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2392 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6805 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7118 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7119 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7120 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7121 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7122 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7124 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7125 https://bugzilla.redhat.com/show_bug.cgi?id=824411 http://www.openwall.com/lists/oss-security/2012/05/23/17 Description: Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors. Ubuntu-Description: Notes: jdstrand> Per Debian, not suitable for code injection Bugs: Priority: negligible Discovered-by: Laurent Butti Assigned-to: CVSS: Patches_wireshark: upstream_wireshark: released (1.4.13, 1.6.8-1) hardy_wireshark: ignored (reached end-of-life) lucid_wireshark: not-affected (1.2.7-1) natty_wireshark: ignored (reached end-of-life) oneiric_wireshark: ignored (reached end-of-life) precise_wireshark: ignored (reached end-of-life) precise/esm_wireshark: DNE (precise was needed) quantal_wireshark: not-affected (1.6.8-1) raring_wireshark: not-affected (1.6.8-1) saucy_wireshark: not-affected (1.6.8-1) trusty_wireshark: not-affected (1.6.8-1) trusty/esm_wireshark: not-affected (1.6.8-1) utopic_wireshark: not-affected (1.6.8-1) vivid_wireshark: not-affected (1.6.8-1) vivid/stable-phone-overlay_wireshark: DNE vivid/ubuntu-core_wireshark: DNE wily_wireshark: not-affected (1.6.8-1) xenial_wireshark: not-affected (1.6.8-1) yakkety_wireshark: not-affected (1.6.8-1) zesty_wireshark: not-affected (1.6.8-1) devel_wireshark: not-affected (1.6.8-1)