CVE-2013-1584: Input Validation
The dissectversion5and6primaryheader function in epan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1584?
CVE-2013-1584 is classified as a denial of service vulnerability that can cause an application crash.
How do I fix CVE-2013-1584?
To fix CVE-2013-1584, you should upgrade to Wireshark version 1.6.13 or later, or 1.8.5 or later.
What versions of Wireshark are affected by CVE-2013-1584?
CVE-2013-1584 affects Wireshark versions 1.6.0 through 1.6.12 and 1.8.0 through 1.8.4.
What are the potential impacts of CVE-2013-1584?
The potential impact of CVE-2013-1584 is that an attacker can crash the application by sending a malformed packet.
Is CVE-2013-1584 a critical vulnerability?
While CVE-2013-1584 is significant, it is primarily a denial of service issue rather than a critical remote code execution vulnerability.