SB2013052115 - NULL pointer dereference in wireshark (Alpine package)
Published: May 21, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2013-3559)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via a malformed packet.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c624044ab2ea8c94b1c097ee5f6b40882beb0876
- https://git.alpinelinux.org/aports/commit/?id=43633e589d8ef5a4f3b4aeb7117fac6620f8b7f4
- https://git.alpinelinux.org/aports/commit/?id=e0bbe7644dc4e52485a5d9b1c1f8c559e2aaead4
- https://git.alpinelinux.org/aports/commit/?id=f1a3e9fc5c70002d71a050eeeb78653c1261bc42