Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2013-2488 | First vendor Publication | 2013-03-07 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2488 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:16672 | |||
Oval ID: | oval:org.mitre.oval:def:16672 | ||
Title: | The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location | ||
Description: | The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2013-2488 | Version: | 4 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows XP Microsoft Windows 8 Microsoft Windows Server 2012 | Product(s): | Wireshark |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:20036 | |||
Oval ID: | oval:org.mitre.oval:def:20036 | ||
Title: | DSA-2644-1 wireshark - several | ||
Description: | Multiple vulnerabilities were discovered in the dissectors for the MS-MMS, RTPS, RTPS2, Mount, ACN, CIMD and DTLS protocols, which could result in denial of service or the execution of arbitrary code. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2644-1 CVE-2013-2478 CVE-2013-2480 CVE-2013-2481 CVE-2013-2483 CVE-2013-2484 CVE-2013-2488 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | wireshark |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:25749 | |||
Oval ID: | oval:org.mitre.oval:def:25749 | ||
Title: | SUSE-SU-2013:0714-1 -- Security update for wireshark | ||
Description: | wireshark has been updated to 1.8.6 which fixes bugs and security issues. | ||
Family: | unix | Class: | patch |
Reference(s): | SUSE-SU-2013:0714-1 CVE-2013-2475 CVE-2013-2476 CVE-2013-2477 CVE-2013-2478 CVE-2013-2479 CVE-2013-2480 CVE-2013-2481 CVE-2013-2482 CVE-2013-2483 CVE-2013-2484 CVE-2013-2485 CVE-2013-2486 CVE-2013-2487 CVE-2013-2488 | Version: | 3 |
Platform(s): | SUSE Linux Enterprise Server 11 SUSE Linux Enterprise Server 10 SUSE Linux Enterprise Desktop 11 SUSE Linux Enterprise Desktop 10 | Product(s): | wireshark |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-223.nasl - Type : ACT_GATHER_INFO |
2013-04-29 | Name : The remote SuSE 11 host is missing a security update. File : suse_11_wireshark-130312.nasl - Type : ACT_GATHER_INFO |
2013-04-29 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_wireshark-8500.nasl - Type : ACT_GATHER_INFO |
2013-04-20 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2013-055.nasl - Type : ACT_GATHER_INFO |
2013-03-15 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2644.nasl - Type : ACT_GATHER_INFO |
2013-03-13 | Name : The remote Windows host contains an application that is affected by multiple ... File : wireshark_1_6_14.nasl - Type : ACT_GATHER_INFO |
2013-03-13 | Name : The remote Windows host contains an application that is affected by multiple ... File : wireshark_1_8_6.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:35:05 |
|
2021-05-04 12:25:13 |
|
2021-04-22 01:30:08 |
|
2020-05-23 00:37:06 |
|
2018-10-31 00:20:31 |
|
2018-01-26 12:04:48 |
|
2017-09-19 09:26:00 |
|
2016-04-26 23:08:54 |
|
2015-12-02 17:24:30 |
|
2014-09-23 13:27:21 |
|
2014-06-14 13:35:37 |
|
2014-02-17 11:19:45 |
|
2013-11-04 21:27:10 |
|
2013-05-10 22:30:24 |
|
2013-04-11 13:21:10 |
|
2013-03-08 17:21:11 |
|
2013-03-07 21:19:01 |
|