CVE-2013-4083: Input Validation
The dissectpft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.6.x before 1.6.16, 1.8.x before 1.8.8, and 1.10.0 does not validate a certain fragment length value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4083?
CVE-2013-4083 has a severity rating that may vary, but it is primarily classified as a denial of service vulnerability allowing potential application crashes.
How do I fix CVE-2013-4083?
To fix CVE-2013-4083, upgrade to Wireshark versions 1.6.16, 1.8.8, or 1.10.0 or later which contain the necessary patches.
What software is affected by CVE-2013-4083?
CVE-2013-4083 affects Wireshark versions 1.6.x before 1.6.16, 1.8.x before 1.8.8, and 1.10.0.
What type of vulnerability is CVE-2013-4083?
CVE-2013-4083 is classified as a denial of service vulnerability due to improper validation of fragment length in a dissector.
Can CVE-2013-4083 be exploited remotely?
Yes, CVE-2013-4083 can be exploited remotely by attackers sending specially crafted packets to cause a denial of service.