MEDIUM
wireshark: Infinite loop in the FCSP dissector (wnpa-sec-2013-20, upstream bug 8359)
Published Mar 7, 2013
6.1
MEDIUMCVSS 2.0
EPSS 1.08%
Description
The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 1.6.0
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.8
- 1.6.9
- 1.6.10
- 1.6.11
- 1.6.12
- 1.6.13
No data.
Red Hat Enterprise Linux 5
wireshark
Not affected
Red Hat Enterprise Linux 6
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 6 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not Vulnerable. This issue does not affect the version of wireshark as shipped with Red Hat Enterprise Linux 5 and 6.
Weaknesses (1)
References (13)
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00077.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/52471 third-party-advisoryx_refsource_SECUNIA
- http://www.wireshark.org/docs/relnotes/wireshark-1.6.14.html x_refsource_CONFIRM
- http://www.wireshark.org/docs/relnotes/wireshark-1.8.6.html x_refsource_CONFIRM
- http://www.wireshark.org/security/wnpa-sec-2013-20.html x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/security/cve/CVE-2013-2485 Vendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8359 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=919144 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2431 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2485
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16529 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2013-2485
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 7, 2013
Updated Aug 6, 2024
Reserved Mar 6, 2013
Link CVE-2013-2485
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-2431 Assigner mitre
Published Mar 7, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-2431