Back

MEDIUM

wireshark: Crash in the DTLS dissector (wnpa-sec-2013-22, upstream bug 8380)

Published Mar 7, 2013

Description

The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.

Affected products

Remediation

Red Hat statement

Not Vulnerable. This issue does not affect the version of wireshark as shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 7, 2013
Updated Aug 6, 2024
Reserved Mar 6, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 6, 2013