[2008-09-28] Wireshark 1.0.x .ncf local denial of service

Description

Wireshark 1.0.x crashes as a result of a failed assertion when dealing with a malformed Tamosoft CommView .ncf packet capture:
Err file wtap.c: line 620 (wtap_read): assertion failed: (wth->phdr.pkt_encap != WTAP_ENCAP_PER_PACKET)

POC/Exploit code   [.ncf]

[.ncf]

Other references

Milw0rm : http://www.milw0rm.com/exploits/6622

Securityfocus :