CVE-2013-5717: Input Validation
The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that is not properly handled by the wmemblockalloc function in epan/wmem/wmemallocatorblock.c.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5717?
CVE-2013-5717 has a medium severity rating, indicating potential risks of denial of service.
How do I fix CVE-2013-5717?
The recommended fix for CVE-2013-5717 is to upgrade Wireshark to version 1.10.2 or later, where the vulnerability has been addressed.
Which versions of Wireshark are affected by CVE-2013-5717?
CVE-2013-5717 affects Wireshark versions 1.10.0 and 1.10.1.
Can CVE-2013-5717 be exploited remotely?
Yes, CVE-2013-5717 can be exploited remotely by attackers using specially crafted Bluetooth packets.
What does CVE-2013-5717 lead to if exploited?
If exploited, CVE-2013-5717 can lead to a denial of service by crashing the application.