4.3

CVE-2013-4935

The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Data is provided by the National Vulnerability Database (NVD)
WiresharkWireshark Version1.8.0
WiresharkWireshark Version1.8.1
WiresharkWireshark Version1.8.2
WiresharkWireshark Version1.8.3
WiresharkWireshark Version1.8.4
WiresharkWireshark Version1.8.5
WiresharkWireshark Version1.8.6
WiresharkWireshark Version1.8.7
WiresharkWireshark Version1.8.8
WiresharkWireshark Version1.10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.44% 0.789
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P