Wireshark Multiple Vulnerabilities
Last Update Date:
11 Jun 2013 10:12
Release Date:
11 Jun 2013
3871
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
- An error in the CAPWAP dissector (dissectors/packet-capwap.c) can be exploited to cause a crash via specially crafted packets.
- An error in the GMR-1 BCCH dissector (dissectors/packet-gmr1_bcch.c) can be exploited to cause a crash via specially crafted packets.
- An error in the PPP dissector (dissectors/packet-ppp.c) can be exploited to cause a crash via specially crafted packets.
- An error in the NBAP dissector (dissectors/packet-nbap.c) can be exploited to cause a crash via specially crafted packets.
- An error in the RDP dissector (dissectors/packet-rdp.c) can be exploited to cause a crash via specially crafted packets.
- An error in the GSM CBCH dissector (dissectors/packet-gsm_cbch.c) can be exploited to cause a crash via specially crafted packets.
- An error in the Assa Abloy R3 dissector (dissectors/packet-assa_r3.c) can be exploited to cause excessive memory and CPU consumption.
- An error in the HTTP dissector (dissectors/packet-http.c) when processing certain packets can be exploited to cause a stack overflow via a specially crafted packet.
- An error in the Ixia IxVeriWave file parser (wiretap/vwr.c) when processing certain packets can be exploited to cause a heap-based buffer overflow via a specially crafted packet.
Successful exploitation of this vulnerability may allow execution of arbitrary code.
Impact
- Denial of Service
System / Technologies affected
- Wireshark version 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.6.16 or 1.8.8.
Vulnerability Identifier
- CVE-2013-4074
- CVE-2013-4075
- CVE-2013-4076
- CVE-2013-4077
- CVE-2013-4078
- CVE-2013-4079
- CVE-2013-4080
- CVE-2013-4081
- CVE-2013-4082
- CVE-2013-4083
Source
Related Link
Share with