Show plain JSON{"affected_release": [{"advisory": "RHSA-2013:1569", "cpe": "cpe:/o:redhat:enterprise_linux:6", "package": "wireshark-0:1.8.10-4.el6", "product_name": "Red Hat Enterprise Linux 6", "release_date": "2013-11-20T00:00:00Z"}], "bugzilla": {"description": "wireshark: DoS (crash) in the ISAKMP dissector (wnpa-sec-2012-35)", "id": "881790", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=881790"}, "csaw": false, "cvss": {"cvss_base_score": "4.3", "cvss_scoring_vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "status": "verified"}, "details": ["[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash."], "name": "CVE-2012-5597", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Not affected", "package_name": "wireshark", "product_name": "Red Hat Enterprise Linux 5"}], "public_date": "2012-11-28T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2012-5597\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-5597"], "statement": "This CVE has been rejected. This candidate is a duplicate of CVE-2012-6059. Note: All CVE users should reference CVE-2012-6059 instead of this candidate.", "threat_severity": "Low"}