CVE-2013-4922: Double Free
Published Jul 29, 2013
·Updated
Double free vulnerability in the dissectdcomActivationProperties function in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
1 affected component
Wireshark Wireshark=1.10.0
Remediation
Event History
Jul 29, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4922?
CVE-2013-4922 is considered a moderate severity vulnerability that can lead to a denial of service (application crash).
2
How do I fix CVE-2013-4922?
To mitigate CVE-2013-4922, upgrade to Wireshark version 1.10.1 or later.
3
Which versions of Wireshark are affected by CVE-2013-4922?
CVE-2013-4922 affects Wireshark version 1.10.0.
4
What type of attack can exploit CVE-2013-4922?
CVE-2013-4922 can be exploited by remote attackers via crafted packets, leading to application crashes.
5
Who is responsible for fixing CVE-2013-4922?
The maintainers of Wireshark are responsible for fixing CVE-2013-4922 in the software through updates.