Wireshark Multiple Bugs Let Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1028254 |
|
SecurityTracker URL: http://securitytracker.com/id/1028254
|
|
CVE Reference:
CVE-2013-2475, CVE-2013-2476, CVE-2013-2477, CVE-2013-2479, CVE-2013-2480, CVE-2013-2481, CVE-2013-2482, CVE-2013-2483, CVE-2013-2484, CVE-2013-2485, CVE-2013-2486, CVE-2013-2487, CVE-2013-2488
(Links to External Site)
|
Date: Mar 7 2013
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to versions 1.6.14, 1.8.6
|
Description:
Multiple vulnerabilities were reported in Wireshark. A remote user can cause denial of service conditions.
A remote user can send specially crafted data to cause the target service to hang or crash.
The TCP dissector may crash [CVE-2013-2475]. Versions 1.6.x are not affected.
The HART/IP dissector may enter an infinite loop [CVE-2013-2476]. Versions 1.6.x are not affected.
The CSN.1 dissector may crash [CVE-2013-2477]. Versions 1.6.x are not affected. Laurent Butti reported this vulnerability.
The MS-MMS dissector may crash [CVE-2013-2478]. Laurent Butti reported this vulnerability.
The MPLS Echo dissector may enter an infinite loop [CVE-2013-2479]. Versions 1.6.x are not affected. Laurent Butti reported this vulnerability.
The RTPS and RTPS2 dissector may crash [CVE-2013-2480]. Alyssa Milburn reported this vulnerability.
The Mount dissector may crash [CVE-2013-2481]. Alyssa Milburn reported this vulnerability.
The AMPQ dissector may enter an infinite loop [CVE-2013-2482]. Moshe Kaplan reported this vulnerability.
A divide-by-zero error may occur in the ACN dissector [CVE-2013-2483]. Alyssa Milburn reported this vulnerability.
The CIMD dissector may crash [CVE-2013-2484]. Moshe Kaplan reported this vulnerability.
The FCSP dissector may enter an infinite loop [CVE-2013-2485]. Moshe Kaplan reported this vulnerability.
The DTLS dissector may crash [CVE-2013-2488]. Laurent Butti reported this vulnerability.
The RELOAD dissector may enter an infinite loop [CVE-2013-2486, CVE-2013-2487]. Even Jensen reported this vulnerability.
|
Impact:
A remote user can cause the target service to hang or crash.
|
Solution:
The vendor has issued a fix (1.6.14, 1.8.6).
The vendor's advisory is available at:
http://www.wireshark.org/security/wnpa-sec-2013-10.html
http://www.wireshark.org/security/wnpa-sec-2013-11.html
http://www.wireshark.org/security/wnpa-sec-2013-12.html
http://www.wireshark.org/security/wnpa-sec-2013-13.html
http://www.wireshark.org/security/wnpa-sec-2013-14.html
http://www.wireshark.org/security/wnpa-sec-2013-15.html
http://www.wireshark.org/security/wnpa-sec-2013-16.html
http://www.wireshark.org/security/wnpa-sec-2013-17.html
http://www.wireshark.org/security/wnpa-sec-2013-18.html
http://www.wireshark.org/security/wnpa-sec-2013-19.html
http://www.wireshark.org/security/wnpa-sec-2013-20.html
http://www.wireshark.org/security/wnpa-sec-2013-21.html
http://www.wireshark.org/security/wnpa-sec-2013-22.html
|
Vendor URL: www.wireshark.org/security/wnpa-sec-2013-10.html (Links to External Site)
|
Cause:
State error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 07 Mar 2013 01:51:25 +0000
Subject: Wireshark
|
http://www.wireshark.org/security/wnpa-sec-2013-10.html
http://www.wireshark.org/security/wnpa-sec-2013-11.html
http://www.wireshark.org/security/wnpa-sec-2013-12.html
http://www.wireshark.org/security/wnpa-sec-2013-13.html
http://www.wireshark.org/security/wnpa-sec-2013-14.html
http://www.wireshark.org/security/wnpa-sec-2013-15.html
http://www.wireshark.org/security/wnpa-sec-2013-16.html
http://www.wireshark.org/security/wnpa-sec-2013-17.html
http://www.wireshark.org/security/wnpa-sec-2013-18.html
http://www.wireshark.org/security/wnpa-sec-2013-19.html
http://www.wireshark.org/security/wnpa-sec-2013-20.html
http://www.wireshark.org/security/wnpa-sec-2013-21.html
http://www.wireshark.org/security/wnpa-sec-2013-22.html
CVE-2013-2475
CVE-2013-2476
CVE-2013-2477
CVE-2013-2477
CVE-2013-2479
CVE-2013-2480
CVE-2013-2481
CVE-2013-2482
CVE-2013-2483
CVE-2013-2484
CVE-2013-2485
CVE-2013-2486
CVE-2013-2487
CVE-2013-2488
|
|