CVE-2013-2487
published 2013-03-07CVE-2013-2487: epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data…
PriorityP336high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.36%
87.5th percentile
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 1.8.6-1 (bookworm) | wireshark 1.8.6-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.8.6-1 | 1.8.6-1 |
| wireshark | wireshark | >= 0 < 1.8.6-1 | 1.8.6-1 |
| wireshark | wireshark | >= 0 < 1.8.6-1 | 1.8.6-1 |
| wireshark | wireshark | >= 0 < 1.8.6-1 | 1.8.6-1 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2487]
vendor_redhat·2013-03-06·CVSS 6.1
CVE-2013-2486 [MEDIUM] CWE-835 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2487]
wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2487]
The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet.
Statement: Not Vulnerable. This issue does not affect the version of wireshark as shipped with Red Hat Enterprise Linux 5 and 6.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Red Hat
wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2486]
vendor_redhat·2013-03-06·CVSS 6.1
CVE-2013-2487 [MEDIUM] CWE-835 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2486]
wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2486]
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.
S
Debian
CVE-2013-2487: wireshark - epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELO...
vendor_debian·2013·CVSS 6.1
CVE-2013-2487 [MEDIUM] CVE-2013-2487: wireshark - epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELO...
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid:
GHSA
GHSA-46vr-4pc7-h6ww: epan/dissectors/packet-reload
ghsa_unreviewed·2022-05-14·CVSS 6.1
CVE-2013-2487 [MEDIUM] GHSA-46vr-4pc7-h6ww: epan/dissectors/packet-reload
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.
OSV
CVE-2013-2487: epan/dissectors/packet-reload
osv·2013-03-07·CVSS 6.1
CVE-2013-2487 [MEDIUM] CVE-2013-2487: epan/dissectors/packet-reload
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.
No detection rules found.
No public exploits indexed.
Bugzilla
wireshark: DoS (excessive CPU consumption) in the RELOAD dissector (wnpa-sec-2013-23, upstream #8362, #8546)
bugzilla·2013-05-20·CVSS 6.1
CVE-2013-2486 [MEDIUM] wireshark: DoS (excessive CPU consumption) in the RELOAD dissector (wnpa-sec-2013-23, upstream #8362, #8546)
wireshark: DoS (excessive CPU consumption) in the RELOAD dissector (wnpa-sec-2013-23, upstream #8362, #8546)
Originally, CVE-2013-2486 (bug #CVE-2013-2486) and CVE-2013-2487 (bug #CVE-2013-2487) identifiers have been assigned to a denial of service flaw (excessive CPU consumption and infinite loop) in the RELOAD dissector of Wireshark.
Later it was reported:
[1] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8546#c0
that despite being officially announced the complete patch has not been applied upstream (r47808 was, but r47805 was not). Original r47805 patch has been now applied upstream as revision:
[2] http://anonsvn.wireshark.org/viewvc?view=revision&revision=48677
and whole issue has been corrected in Wireshark 1.8.7 version.
Relevant upstream bug reports:
[3] https://bugs.wi
Bugzilla
wireshark various flaws (fixed in upstream 1.8.6 version) [fedora-18]
bugzilla·2013-03-08·CVSS 6.1
[MEDIUM] wireshark various flaws (fixed in upstream 1.8.6 version) [fedora-18]
wireshark various flaws (fixed in upstream 1.8.6 version) [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for wireshar
Bugzilla
CVE-2013-2486 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2487]
bugzilla·2013-03-07·CVSS 6.1
CVE-2013-2486 [MEDIUM] CVE-2013-2486 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2487]
CVE-2013-2486 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2487]
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2486 to the following vulnerability:
The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2486
[2] http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-reload.c?r1=47805&r2=47804&pathrev=47805
[3] http://anonsvn.wireshark.org/viewvc?view=r
Bugzilla
CVE-2013-2487 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2486]
bugzilla·2013-03-07·CVSS 6.1
CVE-2013-2487 [MEDIUM] CVE-2013-2487 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2486]
CVE-2013-2487 wireshark: Infinite loop in the RELOAD dissector (wnpa-sec-2013-21, upstream bug 8364) [A different flaw than CVE-2013-2486]
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2487 to the following vulnerability:
epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) di
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-reload.c?r1=47808&r2=47807&pathrev=47808http://anonsvn.wireshark.org/viewvc?view=revision&revision=47808http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00077.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00083.htmlhttp://secunia.com/advisories/52471http://secunia.com/advisories/53425http://www.wireshark.org/docs/relnotes/wireshark-1.8.6.htmlhttp://www.wireshark.org/security/wnpa-sec-2013-21.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8364https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16593http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-reload.c?r1=47808&r2=47807&pathrev=47808http://anonsvn.wireshark.org/viewvc?view=revision&revision=47808http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00077.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00083.htmlhttp://secunia.com/advisories/52471http://secunia.com/advisories/53425http://www.wireshark.org/docs/relnotes/wireshark-1.8.6.htmlhttp://www.wireshark.org/security/wnpa-sec-2013-21.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8364https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16593
2013-03-07
Published