CVE-2013-7113Improper Input Validation in Wireshark

Severity
5.0MEDIUMNVD
EPSS
1.0%
top 23.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateMay 17

Description

epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.10.4-1 (bookworm)
Debianwireshark/wireshark< 1.10.4-1+3
NVDwireshark/wireshark4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-73mq-x829-vw7f: epan/dissectors/packet-bssgp2022-05-17
OSV
CVE-2013-7113: epan/dissectors/packet-bssgp2013-12-19

📋Vendor Advisories

2
Red Hat
wireshark: BSSGP dissector could crash (wnpa-sec-2013-67)2013-12-17
Debian
CVE-2013-7113: wireshark - epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before...2013

💬Community

2
Bugzilla
CVE-2013-7113 wireshark: BSSGP dissector could crash (wnpa-sec-2013-67)2013-12-18
Bugzilla
CVE-2013-7112 CVE-2013-7113 CVE-2013-7114 wireshark: various flaws [fedora-all]2013-12-18