CVE-2013-1578: Input Validation
The dissectpwethheuristic function in epan/dissectors/packet-pw-eth.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle apparent Ethernet address values at the beginning of MPLS data, which allows remote attackers to cause a denial of service (loop) via a malformed packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1578?
CVE-2013-1578 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2013-1578?
To fix CVE-2013-1578, users should upgrade to Wireshark version 1.6.13 or later, or 1.8.5 or later.
What versions of Wireshark are affected by CVE-2013-1578?
CVE-2013-1578 affects Wireshark versions 1.6.0 through 1.6.12 and 1.8.0 through 1.8.4.
What attack vector is associated with CVE-2013-1578?
CVE-2013-1578 allows remote attackers to exploit malformed Ethernet address values to trigger a denial of service.
Is there a workaround for CVE-2013-1578?
There are no known workarounds for CVE-2013-1578 other than upgrading to a patched version of Wireshark.