
CVE-2013-3556 – Gentoo Linux Security Advisory 201308-05
https://notcve.org/view.php?id=CVE-2013-3556
25 May 2013 — The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. La función fragment_add_seq_common en epan/reassemble.c en el disector ASN.1 BER en Wireshark antes de r48943 tiene una referencia a un puntero incorrecto durante la comparación, lo que permite a atacantes remotos provocar una denegación d... • http://anonsvn.wireshark.org/viewvc/trunk/epan/reassemble.c?r1=48943&r2=48942&pathrev=48943 • CWE-20: Improper Input Validation •

CVE-2013-2480
https://notcve.org/view.php?id=CVE-2013-2480
07 Mar 2013 — The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet. Los disertores RTPS y TTPS2 en Wireshark v1.6.x antes de v1.6.14 y v1.8.x antes de v1.8.6 permite a atacantes remotos causar una denegación de servicios (caída de aplicación) a través de paquetes malformados. • http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.html •

CVE-2013-2481
https://notcve.org/view.php?id=CVE-2013-2481
07 Mar 2013 — Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_name_snooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value. Error de entero sin signo en la función dissect_mount_dirpath_call en el disector Mount en Wireshark v1.6.x anterior a v1.6.14 y v1.8.x anterior a v1.8.6 cuando nfs_file_name_snooping está... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-mount.c?r1=47672&r2=47671&pathrev=47672 • CWE-189: Numeric Errors •

CVE-2013-2483
https://notcve.org/view.php?id=CVE-2013-2483
07 Mar 2013 — The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data. La función acn_add_dmp_data en epan/dissectors/packet-acn.c en el disector ACN en Wireshark v1.6.x anterior a v1.6.14 y v1.8.x anterior a v1.8.6 permite a atacantes remotos causar una denegación de servicio (error por ... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-acn.c?r1=47692&r2=47691&pathrev=47692 • CWE-189: Numeric Errors •

CVE-2013-2484
https://notcve.org/view.php?id=CVE-2013-2484
07 Mar 2013 — The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet. El disector CIMD en Wireshark v1.6.x anterior a v1.6.14 y v1.8.x anterior a v1.8.6 permite a atacantes remotos causar una denegación de servicio (caida de la aplicación) mediante un paquete malformado. • http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.html •

CVE-2013-2478
https://notcve.org/view.php?id=CVE-2013-2478
07 Mar 2013 — The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string. La función dissect_server_info en epan/dissectors/packet-ms-mms.c en el disertor MS-MMS en Wireshark v1.6.x antes de v1.6.14 y v1.8.x ... • http://anonsvn.wireshark.org/viewvc/trunk-1.8/epan/dissectors/packet-ms-mms.c?r1=47981&r2=47980&pathrev=47981 • CWE-189: Numeric Errors •

CVE-2013-2482
https://notcve.org/view.php?id=CVE-2013-2482
07 Mar 2013 — The AMPQ dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. EL disertor AMPQ en Wireshark v1.6.x antes de v1.6.14 y v1.8.x antes de v1.8.6 permite a atacantes remotos causar una denegación de servicios (bucle infinito) a través de paquetes malformados. • http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.html •

CVE-2013-2485
https://notcve.org/view.php?id=CVE-2013-2485
07 Mar 2013 — The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. El disector FCSP en Wireshark v1.6.x anterior a v1.6.14 y v1.8.x anterior a v1.8.6 permite a atacantes remotos causar una denegación de servicio (bucle infinito) mediante un paquete malformado. • http://lists.opensuse.org/opensuse-updates/2013-03/msg00065.html •

CVE-2013-2488
https://notcve.org/view.php?id=CVE-2013-2488
07 Mar 2013 — The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location. El disector DTLS en Wireshark v1.6.x anterior a v1.6.14 y v1.8.x anterior a v1.8.6 no valida el offset del fragmento antes de invocar el estado de la máquina, permitiendo a atacantes remotos ... • http://anonsvn.wireshark.org/viewvc?view=revision&revision=48011 • CWE-20: Improper Input Validation •

CVE-2013-1574
https://notcve.org/view.php?id=CVE-2013-1574
03 Feb 2013 — The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in the Bluetooth HCI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a counter variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. La función dissect_bthci_eir_ad_data en epan/dissectors/packet-bthci_cmd.c en el dissector Bluetooth HCI en Wireshark v1.6.x anterior a v1.6.13 y v1.8.x anterior a v1.8.5 usa un tipo de datos incor... • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-bthci_cmd.c?r1=46345&r2=46344&pathrev=46345 • CWE-20: Improper Input Validation •