Wireshark Multiple Denial of Service Vulnerabilities
Last Update Date:
30 Jul 2013 12:41
Release Date:
30 Jul 2013
3771
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service).
- An error exists in the DCP ETSI dissector.
- An error in the P1 dissector can be exploited to cause a crash.
Some errors in the DCOM ISystemActivator dissector can be exploited to cause crashes. - An error in the Bluetooth SDP dissector can be exploited to trigger a large loop and consume CPU resources.
- An error in the Bluetooth OBEX dissector can be exploited to trigger an infinite loop and consume excessive CPU resources.
- An error in the DIS dissector can be exploited to trigger a large loop and consume CPU resources.
- An error in the DVB-CI dissector can be exploited to cause a crash.
- Some errors in the GSM dissectors including the GSM RR dissector can be exploited to trigger a large loop and consume CPU resources.
- An error in the GSM A Common dissector can be exploited to cause a crash.
- Some errors in the Netmon file parser can be exploited to cause crashes.
- An error in the ASN.1 PER dissector can be exploited to cause a crash.
The vulnerabilities #5, #7, #8, #9, #10, #11, and #12 are reported in versions 1.10.0 and 1.8.0 through 1.8.8. - An error in the PROFINET Real-Time dissector can be exploited to cause a crash.
The vulnerabilities #1, #2 through #4, #6, and #13 are reported in version 1.10.0.
Impact
- Denial of Service
System / Technologies affected
- Wireshark 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.10.1, 1.8.9, or later.
Vulnerability Identifier
- CVE-2013-4083
- CVE-2013-4920
- CVE-2013-4921
- CVE-2013-4922
- CVE-2013-4923
- CVE-2013-4924
- CVE-2013-4925
- CVE-2013-4926
- CVE-2013-4927
- CVE-2013-4928
- CVE-2013-4929
- CVE-2013-4930
- CVE-2013-4931
- CVE-2013-4932
- CVE-2013-4933
- CVE-2013-4934
- CVE-2013-4935
- CVE-2013-4936
Source
Related Link
Share with