wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.3"
}
],
"vendor_product": "oracle:solaris"
}
]
}