CVE-2013-4081: Buffer Overflow
Published Jun 9, 2013
·Updated
The httppayloadsubdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause a denial of service (stack consumption) via a crafted packet.
Affected Software
28 affected components
Wireshark Wireshark=1.8.0
Wireshark Wireshark=1.8.1
Wireshark Wireshark=1.8.2
Wireshark Wireshark=1.8.3
Wireshark Wireshark=1.8.4
Wireshark Wireshark=1.8.5
Wireshark Wireshark=1.8.6
Wireshark Wireshark=1.8.7
Debian Debian Linux=7.0
openSUSE openSUSE=11.4
openSUSE openSUSE=12.2
openSUSE openSUSE=12.3
Wireshark Wireshark=1.6.0
Wireshark Wireshark=1.6.1
Wireshark Wireshark=1.6.2
Wireshark Wireshark=1.6.3
Wireshark Wireshark=1.6.4
Wireshark Wireshark=1.6.5
Wireshark Wireshark=1.6.6
Wireshark Wireshark=1.6.7
Wireshark Wireshark=1.6.8
Wireshark Wireshark=1.6.9
Wireshark Wireshark=1.6.10
Wireshark Wireshark=1.6.11
Wireshark Wireshark=1.6.12
Wireshark Wireshark=1.6.13
Wireshark Wireshark=1.6.14
Wireshark Wireshark=1.6.15
Event History
Jun 9, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4081?
CVE-2013-4081 is classified as a vulnerability that can lead to a denial of service due to stack consumption.
2
How do I fix CVE-2013-4081?
To fix CVE-2013-4081, update Wireshark to version 1.6.16 or 1.8.8 or later.
3
Which versions of Wireshark are affected by CVE-2013-4081?
CVE-2013-4081 affects Wireshark versions 1.6.x before 1.6.16 and 1.8.x before 1.8.8.
4
Is there a workaround for CVE-2013-4081?
Currently, there is no known workaround for CVE-2013-4081; upgrading is the recommended solution.
5
What components are impacted by CVE-2013-4081?
CVE-2013-4081 impacts the HTTP dissector function in Wireshark.