CVE-2013-2476Infinite Loop in Wireshark

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 26.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 14

Description

The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a packet with a header that is too short.

CVSS vector

AV:A/AC:L/C:N/I:N/A:CExploitability: 6.5 | Impact: 6.9

Affected Packages4 packages

debiandebian/wireshark< wireshark 1.8.6-1 (bookworm)
Debianwireshark/wireshark< 1.8.6-1+3
NVDwireshark/wireshark6 versions+5
NVDopensuse/opensuse4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-m58c-4j5v-qw53: The dissect_hartip function in epan/dissectors/packet-hartip2022-05-14
OSV
CVE-2013-2476: The dissect_hartip function in epan/dissectors/packet-hartip2013-03-07

📋Vendor Advisories

2
Red Hat
wireshark: Infinite loop in the HART/IP dissector (wnpa-sec-2013-11, upstream bug 8360)2013-03-06
Debian
CVE-2013-2476: wireshark - The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP di...2013

💬Community

2
Bugzilla
wireshark various flaws (fixed in upstream 1.8.6 version) [fedora-18]2013-03-08
Bugzilla
CVE-2013-2476 wireshark: Infinite loop in the HART/IP dissector (wnpa-sec-2013-11, upstream bug 8360)2013-03-07