CVE-2013-2478: Integer Overflow
The dissectserverinfo function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2478?
CVE-2013-2478 has been classified as a denial of service vulnerability due to potential application crashes.
What versions of Wireshark are affected by CVE-2013-2478?
Wireshark versions 1.6.x before 1.6.14 and 1.8.x before 1.8.6 are affected by CVE-2013-2478.
How do I fix CVE-2013-2478?
To fix CVE-2013-2478, upgrade Wireshark to version 1.6.14 or later, or 1.8.6 or later.
What is the impact of CVE-2013-2478 on users?
The impact of CVE-2013-2478 allows remote attackers to disrupt the application, potentially leading to service downtime.
Which operating systems are vulnerable to CVE-2013-2478?
CVE-2013-2478 affects multiple operating systems including Debian and openSUSE versions specified.