Release date:
Updated on:
Affected Systems:
Wireshark 1.8.x
Wireshark 1.6.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-1578
Wireshark is the most popular network protocol parser.
Wireshark 1.6.x, 1.8.x epan/dissectors/The dissect_pw_eth_heuristic function of the packet-pw-eth.c does not properly process the ethernet address before MPLS data, which allows remote attackers to cause application crashes and DOS through malformed packets.
<* Source: Laurent Butti
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2013-1578
Http://www.wireshark.org/security/wnpa-sec-2013-01.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Wireshark
---------
Wireshark has released a Security Bulletin (wnpa-sec-2013-01) and corresponding patches for this:
Wnpa-sec-2013-01: Infinite and large loops in several dissectors.
Link: http://www.wireshark.org/security/wnpa-sec-2013-01.html