Bug 836960 (CVE-2012-3825) - CVE-2012-3825 wireshark: Integer overflows in BACapp and Bluetooth HCI dissectors, leading to DoS (wnpa-sec-2012-08)
Summary: CVE-2012-3825 wireshark: Integer overflows in BACapp and Bluetooth HCI dissec...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-3825
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 824426 994924 1004712
Blocks: 824434 974906
TreeView+ depends on / blocked
 
Reported: 2012-07-02 10:27 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:53 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-06-08 20:00:47 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:1569 normal SHIPPED_LIVE Moderate: wireshark security, bug fix, and enhancement update 2013-11-20 21:40:01 UTC

Description Jan Lieskovsky 2012-07-02 10:27:49 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3825 to the following vulnerability:

Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) BACapp and (2) Bluetooth HCI dissectors, a different vulnerability than CVE-2012-2392.

References:
[1] http://www.wireshark.org/security/wnpa-sec-2012-08.html
[2] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7121
[3] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7122

Comment 1 Huzaifa S. Sidhpurwala 2012-07-05 04:51:34 UTC
There are essentially two issues in this CVE, one dealing with BACapp and the other with Bluetooth HCI. The Bluetooth HCI dissector issue affects Red Hat Enterprise Linux 6.

Comment 4 errata-xmlrpc 2013-11-21 07:29:18 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:1569 https://rhn.redhat.com/errata/RHSA-2013-1569.html

Comment 5 Huzaifa S. Sidhpurwala 2013-11-22 03:11:17 UTC
Statement:

(none)

Comment 6 Martin Žember 2015-06-08 19:47:38 UTC
RHEL-5 is affected by the HCI Bluetooth variant of the bug.

Comment 7 Tomas Hoger 2015-06-08 20:00:47 UTC
Red Hat Enterprise Linux 5 is currently in Phase 3 of its life cycle, during which only Critical impact security issues are expected to get fixed.  This Low impact issue will not be considered for exception.


Note You need to log in before you can comment on or make changes to this bug.