CVE-2013-1587: Low severity Wireshark Wireshark vulnerability
The dissectrohcirpacket function in epan/dissectors/packet-rohc.c in the ROHC dissector in Wireshark 1.8.x before 1.8.5 does not properly handle unknown profiles, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1587?
CVE-2013-1587 has been classified as a high severity vulnerability due to its potential to cause denial of service through application crashes.
How do I fix CVE-2013-1587?
To fix CVE-2013-1587, update Wireshark to version 1.8.5 or later, where the issue has been resolved.
Which versions of Wireshark are affected by CVE-2013-1587?
CVE-2013-1587 affects Wireshark versions 1.6.0 to 1.6.12 and 1.8.0 to 1.8.4.
What type of attack does CVE-2013-1587 enable?
CVE-2013-1587 enables remote attackers to execute a denial of service attack, leading to application crashes via malformed packets.
Is CVE-2013-1587 still a concern in the latest Wireshark releases?
No, CVE-2013-1587 is no longer a concern in Wireshark versions released after 1.8.5, as the vulnerability has been patched.