CVE-2013-1589
Mandriva Linux Security Advisory 2013-020
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Double free vulnerability in epan/proto.c in the dissection engine in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Vulnerabilidad de doble liberación en epan/proto.c en el motor de disección en Wireshark v1.6.x antes de v1.6.13 y v1.8.x antes de v1.8.5 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) a través de un paquete mal formado.
Multiple vulnerabilities was found and corrected in Wireshark. Fixes focused on infinite loops and crashes in various dissectors. This advisory provides the latest version of Wireshark which is not vulnerable to these issues.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-01-30 CVE Reserved
- 2013-02-03 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://anonsvn.wireshark.org/viewvc?view=revision&revision=47114 | X_refsource_confirm | |
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8197 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16319 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://anonsvn.wireshark.org/viewvc/trunk/epan/proto.c?r1=47114&r2=47113&pathrev=47114 | 2017-09-19 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2013-02/msg00028.html | 2017-09-19 | |
http://lists.opensuse.org/opensuse-updates/2013-02/msg00037.html | 2017-09-19 | |
http://www.wireshark.org/security/wnpa-sec-2013-08.html | 2017-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.0 Search vendor "Wireshark" for product "Wireshark" and version "1.6.0" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.1 Search vendor "Wireshark" for product "Wireshark" and version "1.6.1" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.2 Search vendor "Wireshark" for product "Wireshark" and version "1.6.2" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.3 Search vendor "Wireshark" for product "Wireshark" and version "1.6.3" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.4 Search vendor "Wireshark" for product "Wireshark" and version "1.6.4" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.5 Search vendor "Wireshark" for product "Wireshark" and version "1.6.5" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.6 Search vendor "Wireshark" for product "Wireshark" and version "1.6.6" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.7 Search vendor "Wireshark" for product "Wireshark" and version "1.6.7" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.8 Search vendor "Wireshark" for product "Wireshark" and version "1.6.8" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.9 Search vendor "Wireshark" for product "Wireshark" and version "1.6.9" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.10 Search vendor "Wireshark" for product "Wireshark" and version "1.6.10" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.11 Search vendor "Wireshark" for product "Wireshark" and version "1.6.11" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.6.12 Search vendor "Wireshark" for product "Wireshark" and version "1.6.12" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.8.0 Search vendor "Wireshark" for product "Wireshark" and version "1.8.0" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.8.1 Search vendor "Wireshark" for product "Wireshark" and version "1.8.1" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.8.2 Search vendor "Wireshark" for product "Wireshark" and version "1.8.2" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.8.3 Search vendor "Wireshark" for product "Wireshark" and version "1.8.3" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.8.4 Search vendor "Wireshark" for product "Wireshark" and version "1.8.4" | - |
Affected
|