Wireshark CVE-2013-4080 Denial of Service Vulnerability
BID:60503
Info
Wireshark CVE-2013-4080 Denial of Service Vulnerability
| Bugtraq ID: | 60503 |
| Class: | Unknown |
| CVE: |
CVE-2013-4080 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2013 12:00AM |
| Updated: | May 07 2015 05:12PM |
| Credit: | Jeff Morriss |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Wireshark CVE-2013-4080 Denial of Service Vulnerability
Wireshark is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions.
Wireshark versions 1.8.0 through 1.8.7 are vulnerable.
Note: This issue was previously discussed in BID 60448 (Wireshark Multiple Buffer Overflow and Denial of Service), but has been moved to its own record for better documentation.
Wireshark is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions.
Wireshark versions 1.8.0 through 1.8.7 are vulnerable.
Note: This issue was previously discussed in BID 60448 (Wireshark Multiple Buffer Overflow and Denial of Service), but has been moved to its own record for better documentation.
Exploit / POC
Wireshark CVE-2013-4080 Denial of Service Vulnerability
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
A sample packet trace file is available in the Wireshark bug report. Please see the references for more information.
Solution / Fix
Wireshark CVE-2013-4080 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark CVE-2013-4080 Denial of Service Vulnerability
References:
References:
- Bug 8764 - Fuzz failure (out of memory / more than 100000 items in tree in assa_ (Wireshark)
- Wireshark 1.8.8 Release Notes (Wireshark)
- Wireshark Homepage (Wireshark)
- wnpa-sec-2013-38 (Wireshark)