CVE-2012-5597
Description
[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.
Statement
This CVE has been rejected. This candidate is a duplicate of CVE-2012-6059. Note: All CVE users should reference CVE-2012-6059 instead of this candidate.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v2 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 4.3 | N/A | N/A |
| Attack Vector | Network | N/A | N/A |
| Access Complexity | Medium | N/A | N/A |
| Authentication | None | N/A | N/A |
| Confidentiality Impact | None | N/A | N/A |
| Integrity Impact | None | N/A | N/A |
| Availability Impact | Partial | N/A | N/A |
Vector
Red Hat: AV:N/AC:M/Au:N/C:N/I:N/A:P
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.