Wireshark PPP CCP Dissector Denial of Service Vulnerability
BID:59994
Info
Wireshark PPP CCP Dissector Denial of Service Vulnerability
| Bugtraq ID: | 59994 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-3558 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2013 12:00AM |
| Updated: | Apr 13 2015 09:37PM |
| Credit: | Wireshark |
| Vulnerable: |
Wireshark Wireshark 1.8.6 Wireshark Wireshark 1.8.5 Wireshark Wireshark 1.8.4 Wireshark Wireshark 1.8.3 Wireshark Wireshark 1.8.2 Wireshark Wireshark 1.8.1 Wireshark Wireshark 1.8.0 S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 S.u.S.E. openSUSE 11.4 Oracle Solaris 11.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Wireshark Wireshark 1.8.7 Oracle Solaris 11.1.11.4.0 |
Discussion
Wireshark PPP CCP Dissector Denial of Service Vulnerability
Wireshark is prone to a denial-of-service vulnerability because it fails to properly allocate memory.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark versions 1.8.0 through 1.8.6 are vulnerable.
Wireshark is prone to a denial-of-service vulnerability because it fails to properly allocate memory.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark versions 1.8.0 through 1.8.6 are vulnerable.
Exploit / POC
Wireshark PPP CCP Dissector Denial of Service Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
[email protected]
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
[email protected]
Solution / Fix
Wireshark PPP CCP Dissector Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark PPP CCP Dissector Denial of Service Vulnerability
References:
References:
- Bug 8638 - Dissector PPP CCP crash wireshark (Wireshark)
- Multiple vulnerabilities in Wireshark (Oracle)
- PPP CCP dissector crash (Wireshark)
- Wireshark 1.8.7 Release Notes (Wireshark)
- Wireshark Homepage (Wireshark)