Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:WIRESHARK-CAPWAP

Severity

Minor

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

Wireshark CAPWAP Dissector Denial of Service

Release Date

2017/05/03

Update Number

2884

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: Wireshark CAPWAP Dissector Denial of Service


This signature detects attempts to exploit a known vulnerability against Wireshark. A successful attack can result in a denial-of-service condition.

Extended Description

The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Affected Products

  • Debian debian_linux 7.0
  • Opensuse opensuse 11.4
  • Opensuse opensuse 12.2
  • Opensuse opensuse 12.3
  • Wireshark wireshark 1.6.0
  • Wireshark wireshark 1.6.1
  • Wireshark wireshark 1.6.10
  • Wireshark wireshark 1.6.11
  • Wireshark wireshark 1.6.12
  • Wireshark wireshark 1.6.13
  • Wireshark wireshark 1.6.14
  • Wireshark wireshark 1.6.15
  • Wireshark wireshark 1.6.2
  • Wireshark wireshark 1.6.3
  • Wireshark wireshark 1.6.4
  • Wireshark wireshark 1.6.5
  • Wireshark wireshark 1.6.6
  • Wireshark wireshark 1.6.7
  • Wireshark wireshark 1.6.8
  • Wireshark wireshark 1.6.9
  • Wireshark wireshark 1.8.0
  • Wireshark wireshark 1.8.1
  • Wireshark wireshark 1.8.2
  • Wireshark wireshark 1.8.3
  • Wireshark wireshark 1.8.4
  • Wireshark wireshark 1.8.5
  • Wireshark wireshark 1.8.6
  • Wireshark wireshark 1.8.7

References

  • CVE: CVE-2013-4074

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out