CVE-2013-4928: High severity wireshark vulnerability
Published Jul 29, 2013
·Updated
Integer signedness error in the dissectheaders function in epan/dissectors/packet-btobex.c in the Bluetooth OBEX dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Affected Software
1 affected component
Wireshark Wireshark=1.10.0
Remediation
Event History
Jul 29, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4928?
CVE-2013-4928 has a moderate severity level as it allows remote attackers to cause a denial of service.
2
How do I fix CVE-2013-4928?
To fix CVE-2013-4928, update Wireshark to version 1.10.1 or later.
3
What component of Wireshark is affected by CVE-2013-4928?
CVE-2013-4928 affects the Bluetooth OBEX dissector in Wireshark.
4
Can CVE-2013-4928 result in data loss?
CVE-2013-4928 does not specifically lead to data loss, but it causes an infinite loop leading to denial of service.
5
Which versions of Wireshark are impacted by CVE-2013-4928?
Wireshark versions prior to 1.10.1, specifically version 1.10.0, are impacted by CVE-2013-4928.