CVE Vulnerabilities

CVE-2013-2478

Published: Mar 07, 2013 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded 0 characters in a string.

Affected Software

Name Vendor Start Version End Version
Debian_linux Debian 7.0 (including) 7.0 (including)
Opensuse Opensuse 11.4 (including) 11.4 (including)
Opensuse Opensuse 12.1 (including) 12.1 (including)
Opensuse Opensuse 12.2 (including) 12.2 (including)
Opensuse Opensuse 12.3 (including) 12.3 (including)
Wireshark Ubuntu hardy *
Wireshark Ubuntu lucid *
Wireshark Ubuntu oneiric *
Wireshark Ubuntu precise *
Wireshark Ubuntu quantal *
Wireshark Ubuntu raring *
Wireshark Ubuntu saucy *
Wireshark Ubuntu upstream *

References