Input validation error in Wireshark - CVE-2013-2488

 

Input validation error in Wireshark - CVE-2013-2488

Published: March 7, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32719
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2488
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.


Affected software

Wireshark
wireshark (Alpine package)

How to mitigate CVE-2013-2488

Install update from vendor's website.

Wireshark - update to 1.6.14
wireshark (Alpine package) - update to 1.6.14-r0

External References

Related Security Bulletins