PT-2013-3820 · Wireshark+1 · Wireshark+1

Publicado

2013-03-07

·

Atualizado

2024-06-15

·

CVE-2013-2487

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.8.x through 1.8.5
Description The issue is related to the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark, where incorrect integer data types are used. This allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet. The affected functions include dissect icecandidates, dissect kinddata, dissect nodeid list, dissect storeans, dissect storereq, dissect storeddataspecifier, dissect fetchreq, dissect findans, dissect diagnosticinfo, dissect diagnosticresponse, dissect reload messagecontents, and dissect reload message.
Recommendations For Wireshark versions 1.8.x through 1.8.5, update to version 1.8.6 or later to resolve the issue. As a temporary workaround, consider disabling the affected dissector functions until a patch is available. Restrict access to the vulnerable epan/dissectors/packet-reload.c module to minimize the risk of exploitation. Avoid using crafted integer values in packets to prevent denial of service attacks.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2487
DLA-497-1
MGASA-2013-0168
OPENSUSE-SU-2024:10199-1
SUSE-SU-2015:0426-1
SUSE-SU-2015:0653-1
SUSE-SU-2015:1098-1

Produtos afetados

Suse
Wireshark