CVE-2013-4074: Medium severity Wireshark Wireshark vulnerability
The dissectcapwapdata function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4074?
CVE-2013-4074 has been classified as a high-severity vulnerability that can lead to a denial of service.
How do I fix CVE-2013-4074?
To fix CVE-2013-4074, update Wireshark to version 1.6.16 or 1.8.8 or later.
Which versions of Wireshark are affected by CVE-2013-4074?
CVE-2013-4074 affects Wireshark versions 1.6.x prior to 1.6.16 and 1.8.x prior to 1.8.8.
Can CVE-2013-4074 be exploited remotely?
Yes, CVE-2013-4074 can be exploited remotely to crash the application.
What is the nature of the issue in CVE-2013-4074?
CVE-2013-4074 involves incorrect error handling in the dissect_capwap_data function leading to an application crash.