« Volver al listado

CVE-2012-5240

Estado: ModificadaMedia (5.8)—

Desbordamiento de búfer en la función dissect_tlv en epan/dissectors/packet-ldp.c en el "dissector" LDP en Wireshark v1.8.x antiores a v1.8.3 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o posiblemente tener otro impacto no especificado a través de un paquete mal formado.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5240",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-04T19:55:00.963",
  "references": [
    {
      "url": "http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ldp.c?r1=44801&r2=44800&pathrev=44801",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://anonsvn.wireshark.org/viewvc?view=revision&revision=44801",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/55754",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1027604",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wireshark.org/security/wnpa-sec-2012-29.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7046",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7567",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15691",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ldp.c?r1=44801&r2=44800&pathrev=44801",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://anonsvn.wireshark.org/viewvc?view=revision&revision=44801",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/55754",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027604",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wireshark.org/security/wnpa-sec-2012-29.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7046",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7567",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15691",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en la función dissect_tlv en epan/dissectors/packet-ldp.c en el \"dissector\" LDP en Wireshark v1.8.x antiores a v1.8.3 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o posiblemente tener otro impacto no especificado a través de un paquete mal formado."
    }
  ],
  "lastModified": "2026-06-16T23:46:29.930",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:1.8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "606DF728-1DA6-4989-B40A-44471CC677DB"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:1.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F824AE6B-B087-4C69-8F73-7B146920FC3C"
            },
            {
              "criteria": "cpe:2.3:a:wireshark:wireshark:1.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6702EAA1-7FBD-4755-B7C2-C2B3A1AFF142"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}