CVE Vulnerabilities

CVE-2013-4927

Published: Jul 30, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark1.8.0 (including)1.8.0 (including)
WiresharkWireshark1.8.1 (including)1.8.1 (including)
WiresharkWireshark1.8.2 (including)1.8.2 (including)
WiresharkWireshark1.8.3 (including)1.8.3 (including)
WiresharkWireshark1.8.4 (including)1.8.4 (including)
WiresharkWireshark1.8.5 (including)1.8.5 (including)
WiresharkWireshark1.8.6 (including)1.8.6 (including)
WiresharkWireshark1.8.7 (including)1.8.7 (including)
WiresharkWireshark1.8.8 (including)1.8.8 (including)
Red Hat Enterprise Linux 5RedHatwireshark-0:1.0.15-6.el5_10*
Red Hat Enterprise Linux 6RedHatwireshark-0:1.8.10-4.el6*
WiresharkUbuntulucid*
WiresharkUbuntuprecise*
WiresharkUbuntuquantal*
WiresharkUbunturaring*
WiresharkUbuntuupstream*

References