PT-2013-3820 · Wireshark+1 · Wireshark+1

Published

2013-03-07

·

Updated

2024-06-15

·

CVE-2013-2487

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.8.x through 1.8.5
Description The issue is related to the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark, where incorrect integer data types are used. This allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet. The affected functions include dissect icecandidates, dissect kinddata, dissect nodeid list, dissect storeans, dissect storereq, dissect storeddataspecifier, dissect fetchreq, dissect findans, dissect diagnosticinfo, dissect diagnosticresponse, dissect reload messagecontents, and dissect reload message.
Recommendations For Wireshark versions 1.8.x through 1.8.5, update to version 1.8.6 or later to resolve the issue. As a temporary workaround, consider disabling the affected dissector functions until a patch is available. Restrict access to the vulnerable epan/dissectors/packet-reload.c module to minimize the risk of exploitation. Avoid using crafted integer values in packets to prevent denial of service attacks.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2487
DLA-497-1
MGASA-2013-0168
OPENSUSE-SU-2024:10199-1
SUSE-SU-2015:0426-1
SUSE-SU-2015:0653-1
SUSE-SU-2015:1098-1

Affected Products

Suse
Wireshark