7.8
CVSSv2

CVE-2013-2487

Published: 07/03/2013 Updated: 30/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x prior to 1.8.6 uses incorrect integer data types, which allows remote malicious users to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 11.4

opensuse opensuse 12.1

opensuse opensuse 12.2

opensuse opensuse 12.3

debian debian linux 7.0

wireshark wireshark 1.8.2

wireshark wireshark 1.8.3

wireshark wireshark 1.8.0

wireshark wireshark 1.8.1

wireshark wireshark 1.8.4

wireshark wireshark 1.8.5

Vendor Advisories

Debian Bug report logs - #709167 wireshark: Security vulnerabilities fixed in 187 (CVE-2013-3555 to CVE-2013-3562) Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Tue, 21 May ...