Wireshark CVE-2013-4074 Denial of Service Vulnerability
BID:60500
Info
Wireshark CVE-2013-4074 Denial of Service Vulnerability
| Bugtraq ID: | 60500 |
| Class: | Unknown |
| CVE: |
CVE-2013-4074 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2013 12:00AM |
| Updated: | May 07 2015 05:15PM |
| Credit: | Wireshark |
| Vulnerable: |
Wireshark Wireshark 1.8.7 Wireshark Wireshark 1.8.6 Wireshark Wireshark 1.8.5 Wireshark Wireshark 1.8.4 Wireshark Wireshark 1.6.15 Wireshark Wireshark 1.6.14 Wireshark Wireshark 1.6.13 Wireshark Wireshark 1.6.12 Wireshark Wireshark 1.6.11 Wireshark Wireshark 1.6.10 Wireshark Wireshark 1.6.9 Wireshark Wireshark 1.6.8 Wireshark Wireshark 1.6.7 Wireshark Wireshark 1.6.6 Wireshark Wireshark 1.6.5 Wireshark Wireshark 1.6.4 Wireshark Wireshark 1.6.3 Wireshark Wireshark 1.6.2 Wireshark Wireshark 1.6.1 Wireshark Wireshark 1.6 Wireshark Wireshark 1.8.3 Wireshark Wireshark 1.8.2 Wireshark Wireshark 1.8.1 Wireshark Wireshark 1.8.0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Wireshark Wireshark 1.8.8 Wireshark Wireshark 1.6.16 |
Discussion
Wireshark CVE-2013-4074 Denial of Service Vulnerability
Wireshark is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions.
Wireshark versions 1.6.0 through 1.6.15 and 1.8.0 through 1.8.7 are vulnerable.
Note: This issue was previously discussed in BID 60448 (Wireshark Multiple Buffer Overflow and Denial of Service), but has been moved to its own record for better documentation.
Wireshark is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions.
Wireshark versions 1.6.0 through 1.6.15 and 1.8.0 through 1.8.7 are vulnerable.
Note: This issue was previously discussed in BID 60448 (Wireshark Multiple Buffer Overflow and Denial of Service), but has been moved to its own record for better documentation.
Exploit / POC
Wireshark CVE-2013-4074 Denial of Service Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
The following exploit is available:
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
The following exploit is available:
Solution / Fix
Wireshark CVE-2013-4074 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva dumpcap-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark-devel-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark1-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rawshark-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tshark-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-tools-1.6.16-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva dumpcap-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libwireshark-devel-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libwireshark1-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rawshark-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tshark-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-tools-1.6.16-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva dumpcap-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark-devel-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark1-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rawshark-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tshark-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-tools-1.6.16-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Wireshark CVE-2013-4074 Denial of Service Vulnerability
References:
References:
- Bug 8725 - CAPWAP dissector crash (Wireshark)
- Wireshark 1.6.16 Release Notes (Wireshark)
- Wireshark 1.8.8 Release Notes (Wireshark)
- Wireshark Homepage (Wireshark)
- wnpa-sec-2013-32 (Wireshark)