CVE-2013-4927 – wireshark: Integer signedness error in the Bluetooth SDP dissector (wnpa-sec-2013-45)
https://notcve.org/view.php?id=CVE-2013-4927
Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet. Error de entero sin signo en la función get_type_length en epan/dissectors/packet-btsdp.c del disector Bluetooth SDP de Wireshark 1.8.x anterior a 1.8.9 y 1.10.x anterior 1.10.1, permite a atacantes remotos provocar una denegación de servicio (bucle y consumo de CPU) a través de un paquete manipulado. • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-btsdp.c?r1=50134&r2=50133&pathrev=50134 http://anonsvn.wireshark.org/viewvc?view=revision&revision=50134 http://lists.opensuse.org/opensuse-updates/2013-08/msg00004.html http://lists.opensuse.org/opensuse-updates/2013-08/msg00009.html http://rhn.redhat.com/errata/RHSA-2014-0341.html http://secunia.com/advisories/54296 http://secunia.com/advisories/54371 http://secunia.com/advisories/54425 http://www.gentoo.org/security/ • CWE-189: Numeric Errors •
CVE-2013-4936 – wireshark: DoS (NULL pointer dereference, crash) in the PROFINET Real-Time dissector (wnpa-sec-2013-53)
https://notcve.org/view.php?id=CVE-2013-4936
The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not validate MAC addresses, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. La función dissect_smtp en epan/dissectors/packet-smtp.c del disector PROFINET Real-Time en Wireshark 1.10.x anterior a 1.10.1 no inicializa determinados miembros estructuras, lo que permite a atacantes remotos provocar una denegación de servicio (deferencia puntero nulo y caída de aplicación) a través de un paquete manipulado. • http://anonsvn.wireshark.org/viewvc/trunk/plugins/profinet/packet-pn-rt.c?r1=50651&r2=50650&pathrev=50651 http://anonsvn.wireshark.org/viewvc?view=revision&revision=50651 http://secunia.com/advisories/54296 http://secunia.com/advisories/54425 http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml http://www.wireshark.org/docs/relnotes/wireshark-1.10.1.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8904 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg • CWE-476: NULL Pointer Dereference •
CVE-2013-4925
https://notcve.org/view.php?id=CVE-2013-4925
Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted packet. Error de entero sin signo en epan/dissectors/packet-dcom-sysact.c del disector DCOM ISystemActivator de Wireshark 1.10.x anterior 1.10.1, permite a atacantes remotos provocar una denegación de servicio (fallo de aserción y cierre de demonio) a través de un paquete manipulado. • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-dcom-sysact.c?r1=50478&r2=50477&pathrev=50478 http://anonsvn.wireshark.org/viewvc?view=revision&revision=50478 http://secunia.com/advisories/54296 http://secunia.com/advisories/54425 http://www.gentoo.org/security/en/glsa/glsa-201308-05.xml http://www.wireshark.org/docs/relnotes/wireshark-1.10.1.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8828 https://oval.cisecurity.org/repository/search/definition/oval%3Ao • CWE-189: Numeric Errors •
CVE-2013-4934 – wireshark: DoS (application crash) in the Netmon file parser (wnpa-sec-2013-51) (A different flaw than CVE-2013-4933)
https://notcve.org/view.php?id=CVE-2013-4934
The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize certain structure members, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace file. La función netmon_open en wiretap/netmon.c del validador de archivos Netmon en Wireshark 1.8.x anterior 1.8.9 y 1.10.x anterior 1.10.1, no inicializa determinados miembros de estructuras, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://anonsvn.wireshark.org/viewvc/trunk/wiretap/netmon.c?r1=49697&r2=49696&pathrev=49697 http://anonsvn.wireshark.org/viewvc?view=revision&revision=49697 http://lists.opensuse.org/opensuse-updates/2013-08/msg00004.html http://lists.opensuse.org/opensuse-updates/2013-08/msg00009.html http://rhn.redhat.com/errata/RHSA-2014-0341.html http://secunia.com/advisories/54178 http://secunia.com/advisories/54296 http://secunia.com/advisories/54371 http://secunia.com/advisories/54425 http:/ • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2013-4935 – wireshark: DoS (application crash) in the ASN.1 PER dissector (wnpa-sec-2013-52)
https://notcve.org/view.php?id=CVE-2013-4935
The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. La función dissect_per_length_determinant en epan/dissectors/packet-smtp.c del disector ASN.1 PER en Wireshark 1.8.x anterior a 1.8.9 y 1.10.x anterior a 1.10.1 no inicializa un tamaño de campo en determinadas situaciones anormales, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-per.c?r1=49985&r2=49984&pathrev=49985 http://anonsvn.wireshark.org/viewvc?view=revision&revision=49985 http://lists.opensuse.org/opensuse-updates/2013-08/msg00004.html http://lists.opensuse.org/opensuse-updates/2013-08/msg00009.html http://rhn.redhat.com/errata/RHSA-2014-0341.html http://secunia.com/advisories/54178 http://secunia.com/advisories/54296 http://secunia.com/advisories/54371 http://secunia.com/advisories/54425 • CWE-189: Numeric Errors •