Wireshark ETCH Dissector Denial of Service Vulnerability
BID:60002
Info
Wireshark ETCH Dissector Denial of Service Vulnerability
| Bugtraq ID: | 60002 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-3561 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2013 12:00AM |
| Updated: | Dec 02 2013 12:47AM |
| Credit: | Moshe Kaplan |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Wireshark ETCH Dissector Denial of Service Vulnerability
Wireshark is prone to a denial-of-service vulnerability because it fails to properly allocate memory.
An attacker can leverage this issue to consume excessive CPU resources, denying service to legitimate users.
Wireshark versions 1.8.0 through 1.8.6 are vulnerable.
Wireshark is prone to a denial-of-service vulnerability because it fails to properly allocate memory.
An attacker can leverage this issue to consume excessive CPU resources, denying service to legitimate users.
Wireshark versions 1.8.0 through 1.8.6 are vulnerable.
Exploit / POC
Wireshark ETCH Dissector Denial of Service Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
[email protected]
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
[email protected]
Solution / Fix
Wireshark ETCH Dissector Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.