Wireshark DCP ETSI Dissector 'dissect_pft_fec_detailed()' Denial of Service Vulnerability
BID:59995
Info
Wireshark DCP ETSI Dissector 'dissect_pft_fec_detailed()' Denial of Service Vulnerability
| Bugtraq ID: | 59995 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-3559 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2013 12:00AM |
| Updated: | Apr 13 2015 09:59PM |
| Credit: | Evan Jensen |
| Vulnerable: |
Wireshark Wireshark 1.8.6 Wireshark Wireshark 1.8.5 Wireshark Wireshark 1.8.4 Wireshark Wireshark 1.8.3 Wireshark Wireshark 1.8.2 Wireshark Wireshark 1.8.1 Wireshark Wireshark 1.8.0 S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 12.2 S.u.S.E. openSUSE 11.4 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle Solaris 11.1 Oracle Enterprise Linux 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya Proactive Contact 5.1 Avaya Proactive Contact 5.0 Avaya one-X Client Enablement Services 6.2 Avaya one-X Client Enablement Services 6.1.2 Avaya one-X Client Enablement Services 6.1.1 Avaya one-X Client Enablement Services 6.1 Avaya one-X Client Enablement Services 6.0 Avaya IP Office Server Edition 9.0 Avaya IP Office Server Edition 8.1 Avaya IP Office Server Edition 8.0 Avaya IP Office Application Server 9.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Aura System Platform 6.2.1 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.3 Avaya Aura System Platform 6.2.1.0.9 Avaya Aura System Platform 6.2 SP1 Avaya Aura System Platform 6.2 Avaya Aura System Platform 6.0.3.9.3 Avaya Aura System Platform 6.0.3.8.3 Avaya Aura System Platform 6.0.3.0.3 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura Session Manager 6.3.1 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.3 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 SP1 Avaya Aura Session Manager 6.2 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Communication Manager 6.3 Avaya Aura Communication Manager 6.2 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Collaboration Environment 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
Wireshark Wireshark 1.8.7 Oracle Solaris 11.1.11.4.0 |
Discussion
Wireshark DCP ETSI Dissector 'dissect_pft_fec_detailed()' Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
Attackers can exploit this issue to cause the application to crash, resulting in denial-of-service conditions.
Wireshark 1.8.0 through versions 1.8.6 are affected.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
Attackers can exploit this issue to cause the application to crash, resulting in denial-of-service conditions.
Wireshark 1.8.0 through versions 1.8.6 are affected.
Exploit / POC
Wireshark DCP ETSI Dissector 'dissect_pft_fec_detailed()' Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Wireshark DCP ETSI Dissector 'dissect_pft_fec_detailed()' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark DCP ETSI Dissector 'dissect_pft_fec_detailed()' Denial of Service Vulnerability
References:
References:
- Bug 8231 - dcp-etsi dissector: formula for rx_min (Wireshark)
- Bug 8541 - Integer Overflow -> Memory Corruption (arbitrary read) packet-dcp-ets (Wireshark)
- DCP ETSI dissector crash (Wireshark)
- Multiple vulnerabilities in Wireshark (Oracle)
- Wireshark Homepage (Wireshark)
- [CentOS-announce] CESA-2014:0341 Moderate CentOS 5 wireshark Update (CentOS)
- \wireshark security, bug fix, and enhancement update (RHSA-2013-1569) (Avaya)
- ASA-2014-176 (Avaya)
- Bug 8540 - Integer Overflow -> Null Pointer Dereference packet-dcp-etsi.c (Wireshark)
- ELSA-2014-0341 Moderate: Oracle Linux 5 wireshark security update (Oracle)
- Moderate: wireshark security update (Red Hat)