Vulnerabilities
Vulnerable Software
Wireshark:  >> Wireshark  >> 1.10.7  Security Vulnerabilities
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.
CVSS Score
5.0
EPSS Score
0.002
Published
2014-08-01
The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CVSS Score
4.3
EPSS Score
0.002
Published
2014-06-18


Contact Us

Shodan ® - All rights reserved