This application requires Javascript for optimal performance.

Wireshark.Insecure.Search.Path.Script.Execution

Release Date

Nov 26, 2011

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a Insecure Search Path vulnerability in Wireshark.

The vulnerability is due to the vulnerable application's failure to sanitize user-supplied input. A remote attacker can exploit this by enticing a user to open a specially crafted pcap file. Successful exploitation may allow attackers to execute arbitrary lua scripts in the context of the running application.

Affected Products

Wireshark Foundation Wireshark 1.4.8 and prior
Wireshark Foundation Wireshark 1.6.1 and prior

Recommended Actions

Apply patches or fixes, available from the website:
http://www.Wireshark.org/security/wnpa-sec-2011-15.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-3360

Reference: VID-30428