Wireshark.Insecure.Search.Path.Script.Execution
Description
This indicates an attempt to exploit a Insecure Search Path vulnerability in Wireshark.
The vulnerability is due to the vulnerable application's failure to sanitize user-supplied input. A remote attacker can exploit this by enticing a user to open a specially crafted pcap file. Successful exploitation may allow attackers to execute arbitrary lua scripts in the context of the running application.
Affected Products
Wireshark Foundation Wireshark 1.4.8 and prior
Wireshark Foundation Wireshark 1.6.1 and prior
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply patches or fixes, available from the website:
http://www.Wireshark.org/security/wnpa-sec-2011-15.html
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |