CVE-2013-4920: Buffer Overflow
Published Jul 29, 2013
·Updated
The P1 dissector in Wireshark 1.10.x before 1.10.1 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
1 affected component
Wireshark Wireshark=1.10.0
Remediation
Event History
Jul 29, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4920?
CVE-2013-4920 has a medium severity level due to its potential to cause application crashes.
2
How do I fix CVE-2013-4920?
To fix CVE-2013-4920, upgrade Wireshark to version 1.10.1 or later.
3
What type of attacks can exploit CVE-2013-4920?
CVE-2013-4920 can be exploited by remote attackers through the sending of crafted packets.
4
Is CVE-2013-4920 present in any other versions of Wireshark?
CVE-2013-4920 is present in Wireshark version 1.10.0 and earlier versions.
5
What impact does CVE-2013-4920 have on users?
The impact of CVE-2013-4920 can result in denial of service due to application crashes when vulnerable versions process malicious packets.