CVE Vulnerabilities

CVE-2013-4927

Published: Jul 30, 2013 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
NEGLIGIBLE

Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 1.8.0 (including) 1.8.0 (including)
Wireshark Wireshark 1.8.1 (including) 1.8.1 (including)
Wireshark Wireshark 1.8.2 (including) 1.8.2 (including)
Wireshark Wireshark 1.8.3 (including) 1.8.3 (including)
Wireshark Wireshark 1.8.4 (including) 1.8.4 (including)
Wireshark Wireshark 1.8.5 (including) 1.8.5 (including)
Wireshark Wireshark 1.8.6 (including) 1.8.6 (including)
Wireshark Wireshark 1.8.7 (including) 1.8.7 (including)
Wireshark Wireshark 1.8.8 (including) 1.8.8 (including)
Red Hat Enterprise Linux 5 RedHat wireshark-0:1.0.15-6.el5_10 *
Red Hat Enterprise Linux 6 RedHat wireshark-0:1.8.10-4.el6 *
Wireshark Ubuntu lucid *
Wireshark Ubuntu precise *
Wireshark Ubuntu quantal *
Wireshark Ubuntu raring *
Wireshark Ubuntu upstream *

References