CVE-2013-3561Infinite Loop in Wireshark

CWE-1897 documents6 sources
Severity
7.8HIGHNVD
EPSS
1.5%
top 18.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateMay 14

Description

Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages4 packages

Ubuntuwireshark/wireshark< 1.10.6-1
NVDwireshark/wireshark7 versions+6
NVDopensuse/opensuse11.4, 12.2, 12.3+2

Also affects: Debian Linux 7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jjj3-h475-4hhm: Multiple integer overflows in Wireshark 12022-05-14
OSV
CVE-2013-3561: Multiple integer overflows in Wireshark 12013-05-25

📋Vendor Advisories

2
Red Hat
wireshark: Multiple Denial of Service flaws2013-05-17
Debian
CVE-2013-3561: wireshark - Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attacker...2013

💬Community

2
Bugzilla
CVE-2013-3561 wireshark: Multiple Denial of Service flaws2013-05-23
Bugzilla
CVE-2013-3562 wireshark: DoS (stack overflow, crash) in the Websocket dissector (wnpa-sec-2013-29, upstream #8448, #8499)2013-05-20