Back

MEDIUM

wireshark: M3UA dissector crash (wnpa-sec-2014-02)

Published Mar 11, 2014

Description

The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the version of wireshark package as shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 11, 2014
Updated Aug 6, 2024
Reserved Mar 5, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 7, 2014