5
CVSSv2

CVE-2014-5163

Published: 01/08/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x prior to 1.10.9 does not completely initialize a certain buffer, which allows remote malicious users to cause a denial of service (application crash) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 1.10.8

wireshark wireshark 1.10.6

wireshark wireshark 1.10.0

wireshark wireshark 1.10.3

wireshark wireshark 1.10.2

wireshark wireshark 1.10.1

wireshark wireshark 1.10.7

wireshark wireshark 1.10.4

wireshark wireshark 1.10.5

Vendor Advisories

Multiple vulnerabilities were discovered in the dissectors for Catapult DCT2000, IrDA, GSM Management, RLC ASN1 BER, which could result in denial of service For the stable distribution (wheezy), these problems have been fixed in version 182-5wheezy11 For the unstable distribution (sid), these problems will be fixed soon We recommend that you ...
Debian Bug report logs - #776135 wireshark: Multiple security issues in 1122 and prior versions Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: balint@balintreczeyhu Date: Sat, 24 Jan 2015 10:51:01 UTC Severity: ...
Debian Bug report logs - #780372 CVE-2015-2187 CVE-2015-2188 CVE-2015-2189 CVE-2015-2190 CVE-2015-2191 CVE-2015-2192 Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Th ...
The APN decode functionality in (1) epan/dissectors/packet-gtpc and (2) epan/dissectors/packet-gsm_a_gmc in the GTP and GSM Management dissectors in Wireshark 110x before 1109 does not completely initialize a certain buffer, which allows remote attackers to cause a denial of service (application crash) via a crafted packet ...