First published: Fri Sep 13 2013(Updated: )
The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that is not properly handled by the wmem_block_alloc function in epan/wmem/wmem_allocator_block.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =1.10.0 | |
Wireshark Wireshark | =1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5717 has a medium severity rating, indicating potential risks of denial of service.
The recommended fix for CVE-2013-5717 is to upgrade Wireshark to version 1.10.2 or later, where the vulnerability has been addressed.
CVE-2013-5717 affects Wireshark versions 1.10.0 and 1.10.1.
Yes, CVE-2013-5717 can be exploited remotely by attackers using specially crafted Bluetooth packets.
If exploited, CVE-2013-5717 can lead to a denial of service by crashing the application.