CVE-2013-2488: Input Validation
The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2488?
CVE-2013-2488 has a severity rating that allows remote attackers to cause a denial of service, leading to application crash.
How do I fix CVE-2013-2488?
To fix CVE-2013-2488, update Wireshark to version 1.6.14 or 1.8.6 or higher.
Which versions of Wireshark are affected by CVE-2013-2488?
CVE-2013-2488 affects Wireshark versions 1.6.x before 1.6.14 and 1.8.x before 1.8.6.
What impact does CVE-2013-2488 have on affected systems?
CVE-2013-2488 can lead to denial of service by crashing the application when processing specially crafted packets.
Can CVE-2013-2488 be exploited remotely?
Yes, CVE-2013-2488 can be exploited remotely, allowing attackers to send malicious packets to crash the application.