3.3
CVSSv2

CVE-2013-2478

Published: 07/03/2013 Updated: 30/10/2018
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x prior to 1.6.14 and 1.8.x prior to 1.8.6 does not properly manage string lengths, which allows remote malicious users to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

opensuse opensuse 12.1

opensuse opensuse 11.4

opensuse opensuse 12.3

opensuse opensuse 12.2

wireshark wireshark 1.6.1

wireshark wireshark 1.6.2

wireshark wireshark 1.6.10

wireshark wireshark 1.6.11

wireshark wireshark 1.6.5

wireshark wireshark 1.6.6

wireshark wireshark 1.6.7

wireshark wireshark 1.6.0

wireshark wireshark 1.6.8

wireshark wireshark 1.6.9

wireshark wireshark 1.6.3

wireshark wireshark 1.6.4

wireshark wireshark 1.6.12

wireshark wireshark 1.6.13

wireshark wireshark 1.8.3

wireshark wireshark 1.8.4

wireshark wireshark 1.8.0

wireshark wireshark 1.8.1

wireshark wireshark 1.8.2

wireshark wireshark 1.8.5

Vendor Advisories

Debian Bug report logs - #776135 wireshark: Multiple security issues in 1122 and prior versions Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: balint@balintreczeyhu Date: Sat, 24 Jan 2015 10:51:01 UTC Severity: ...
Debian Bug report logs - #780372 CVE-2015-2187 CVE-2015-2188 CVE-2015-2189 CVE-2015-2190 CVE-2015-2191 CVE-2015-2192 Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Th ...