CVE
- Id
- 62435
- CVE No.
- CVE-2013-2488
- Status
- Candidate
- Description
- The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.
- Phase
- Assigned (20130306)
- Votes
- None (candidate not yet proposed)
- Comments