CVE-2013-3557: Buffer Overflow
The dissectberchoice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3557?
CVE-2013-3557 has been classified as a medium severity vulnerability due to its potential for causing a denial of service.
How do I fix CVE-2013-3557?
To fix CVE-2013-3557, upgrade Wireshark to version 1.6.15 or 1.8.7 or later.
What versions of Wireshark are affected by CVE-2013-3557?
CVE-2013-3557 affects Wireshark versions prior to 1.6.15 in the 1.6.x line and prior to 1.8.7 in the 1.8.x line.
Can CVE-2013-3557 be exploited remotely?
Yes, CVE-2013-3557 can be exploited remotely through malformed packets.
What is the impact of CVE-2013-3557 on systems?
The impact of CVE-2013-3557 is an application crash, which results in a denial of service condition.