← Back

CVE-2013-1580

nvd nist
Published: Feb 3, 2013Modified: Apr 29, 2026

JSON object

Loading...
2.9
Vector
AV:A/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 5.5 / Impact: 2.9
Source: NVD

Description

The dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in the DOCSIS CM-STATUS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a position variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Affected (18)

Products: Wireshark: Wireshark
1 product
Wireshark
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Wireshark
Version 1.6.0
Version 1.6.10
Version 1.6.11
Version 1.6.12
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.6.6
Version 1.6.7
Version 1.6.8
Version 1.6.9
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Wireshark
Version 1.8.0
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4

References (14)

Timeline

No history available yet.