CVE-2012-5597

Description

[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.

Statement

This CVE has been rejected. This candidate is a duplicate of CVE-2012-6059. Note: All CVE users should reference CVE-2012-6059 instead of this candidate.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v2 Score Breakdown

Red HatNVDcve.org
Base Score4.3N/AN/A
Attack VectorNetworkN/AN/A
Access ComplexityMediumN/AN/A
AuthenticationNoneN/AN/A
Confidentiality ImpactNoneN/AN/A
Integrity ImpactNoneN/AN/A
Availability ImpactPartialN/AN/A

Vector

Red Hat: AV:N/AC:M/Au:N/C:N/I:N/A:P

Frequently Asked Questions

Want to get errata notifications? Sign up here.