CVE

Id
62435  
CVE No.
CVE-2013-2488  
Status
Candidate  
Description
The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.  
Phase
Assigned (20130306)  
Votes
None (candidate not yet proposed)  
Comments