CVE-2013-3561
CVE-2013-3561
Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-etch.c?r1=48919&r2=48918&pathrev=48919http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-mysql.c?r1=48894&r2=48893&pathrev=48894http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-websocket.c?r1=48336&r2=48335&pathrev=48336http://anonsvn.wireshark.org/viewvc?view=revision&revision=48336http://anonsvn.wireshark.org/viewvc?view=revision&revision=48894http://anonsvn.wireshark.org/viewvc?view=revision&revision=48919http://lists.opensuse.org/opensuse-updates/2013-06/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00083.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00194.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00196.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8448https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8458