Wireshark ASSA R3 Dissector CVE-2013-5719 Denial of Service Vulnerability
BID:62318
Info
Wireshark ASSA R3 Dissector CVE-2013-5719 Denial of Service Vulnerability
| Bugtraq ID: | 62318 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-5719 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Dec 17 2013 01:59AM |
| Credit: | Ben Schmidt |
| Vulnerable: |
MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Wireshark ASSA R3 Dissector CVE-2013-5719 Denial of Service Vulnerability
Wireshark is prone to a denial-of-service vulnerability that occurs in the ASSA R3 dissector.
An attacker can exploit this issue to trigger an infinite loop causing the affected application to crash, denying service to legitimate users.
Wireshark versions 1.10.0 through 1.10.1 and 1.8.0 through 1.8.9 are vulnerable.
Wireshark is prone to a denial-of-service vulnerability that occurs in the ASSA R3 dissector.
An attacker can exploit this issue to trigger an infinite loop causing the affected application to crash, denying service to legitimate users.
Wireshark versions 1.10.0 through 1.10.1 and 1.8.0 through 1.8.9 are vulnerable.
Exploit / POC
Wireshark ASSA R3 Dissector CVE-2013-5719 Denial of Service Vulnerability
Attackers can use readily available tools to exploit this issue.
A sample pcap file is available. Please see the references for information.
Attackers can use readily available tools to exploit this issue.
A sample pcap file is available. Please see the references for information.
Solution / Fix
Wireshark ASSA R3 Dissector CVE-2013-5719 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Wireshark ASSA R3 Dissector CVE-2013-5719 Denial of Service Vulnerability
References:
References:
- Wireshark Homepage (Wireshark)