CVE-2013-4931: Medium severity wireshark vulnerability
Published Jul 29, 2013
·Updated
epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop) via a crafted packet that is not properly handled by the GSM RR dissector.
Affected Software
10 affected components
Wireshark Wireshark=1.8.0
Wireshark Wireshark=1.8.1
Wireshark Wireshark=1.8.2
Wireshark Wireshark=1.8.3
Wireshark Wireshark=1.8.4
Wireshark Wireshark=1.8.5
Wireshark Wireshark=1.8.6
Wireshark Wireshark=1.8.7
Wireshark Wireshark=1.8.8
Wireshark Wireshark=1.10.0
Remediation
Event History
Jul 29, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4931?
CVE-2013-4931 has a severity rating that allows remote attackers to cause a denial of service.
2
How can I mitigate CVE-2013-4931?
To mitigate CVE-2013-4931, upgrade to Wireshark version 1.8.9 or higher, or 1.10.1 or higher.
3
Which versions of Wireshark are affected by CVE-2013-4931?
CVE-2013-4931 affects Wireshark versions 1.8.0 through 1.8.8 and 1.10.0.
4
What kind of attack does CVE-2013-4931 enable?
CVE-2013-4931 enables remote attackers to exploit a crafted packet to cause an infinite loop resulting in denial of service.
5
Where can I find more information about CVE-2013-4931?
Information about CVE-2013-4931 can be found in Wireshark's official communication and update logs.