Release date:
Updated on:
Affected Systems:
Wireshark 1.8.x
Wireshark 1.6.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-1582
Wireshark is the most popular network protocol parser.
The dissect_clnp function in epan/dissectors/packet-clnp.c in Wireshark 1.6.x and 1.8.x does not properly manage the offset traversal, which allows remote attackers to cause application crashes and DOS through malformed packets.
<* Source: Laurent Butti
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2013-1582
Http://www.wireshark.org/security/wnpa-sec-2013-02.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
Wireshark has released a Security Bulletin (wnpa-sec-2013-02) and corresponding patches for this:
Wnpa-sec-2013-02: CLNP dissector crash
Link: http://www.wireshark.org/security/wnpa-sec-2013-02.html