wnpa-sec-2013-44 · DCOM ISystemActivator dissector crash
Summary
Name: DCOM ISystemActivator dissector crash
Docid: wnpa-sec-2013-44
Date: July 26, 2013
Affected versions: 1.10.0
Fixed versions: 1.10.1
References:
Wireshark bug 8828
CVE-2013-4922
CVE-2013-4923
CVE-2013-4924
CVE-2013-4925
CVE-2013-4926
Details
Description
The DCOM ISystemActivator dissector could crash. Discovered by Laurent Butti.
Impact
It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Resolution
Upgrade to Wireshark 1.10.1 or later.