Vulnerability Bulletins |
Vulnerabilidades en Wireshark 1.8.X |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Interrupcion del Servicio |
| Dificulty | Avanzado |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | GNU/Linux |
| Affected software | Wireshark versiones 1.8.0 a 1.8.5 |
Description |
|
| Los disectores HART/IP y RELOAD podrían provocar un bucle infinito. La vulnerabilidad consiste en la posibilidad de hacer que Wireshark consuma excesivamente los recursos de la CPU mediante la inyección de paquetes modificados o induciendo a que el usuario lea un archivo de rastreo de paquetes con formato incorrecto. | |
Solution |
|
| Wireshark recomienda actualizar a Wireshark 1.8.6 o versiones posteriores. | |
Standar resources |
|
| Property | Value |
| CVE |
CVE-2013-2476 CVE-2013-2486 CVE-2013-2487 |
| BID | |
Other resources |
|
|
Wireshark: http://www.wireshark.org/security/wnpa-sec-2013-11.html http://www.wireshark.org/security/wnpa-sec-2013-21.html |
|
Version history |
||
| Version | Comments | Date |
| 1,0 | Aviso emitido | 2013-03-08 |
| 1.0 | Aviso emitido | 2013-03-11 |






