Wireshark-bugs: [Wireshark-bugs] [Bug 5133] Wireshark vulnerable to DLL hijacking

Date: Thu, 26 Aug 2010 20:15:34 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5133

--- Comment #11 from Gerald Combs <gerald@xxxxxxxxxxxxx> 2010-08-26 20:15:33 PDT ---
(In reply to comment #10)
> (In reply to comment #9)
> > I've been able to confirm this on Windows 2000. I'm not sure what we can do in
> > this case.
> Would DLL Redirection help?
> http://msdn.microsoft.com/en-us/library/ms682600(v=VS.85).aspx

I tried adding wireshark.exe.local and dumpcap.exe.local to c:\Program
Files\Wireshark on Windows 2000. The airpcap.dll PoC still loaded.

We could skip setting file associations when installing on Windows < XP SP1.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.