SB2013052116 - Format string error in wireshark (Alpine package)
Published: May 21, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Format string error (CVE-ID: CVE-2013-3560)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c624044ab2ea8c94b1c097ee5f6b40882beb0876
- https://git.alpinelinux.org/aports/commit/?id=43633e589d8ef5a4f3b4aeb7117fac6620f8b7f4
- https://git.alpinelinux.org/aports/commit/?id=e0bbe7644dc4e52485a5d9b1c1f8c559e2aaead4
- https://git.alpinelinux.org/aports/commit/?id=f1a3e9fc5c70002d71a050eeeb78653c1261bc42