Description
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3002-1 | wireshark security update |
EUVD |
EUVD-2014-5063 | The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T11:34:37.550Z
Reserved: 2014-07-31T00:00:00.000Z
Link: CVE-2014-5165
No data.
Status : Modified
Published: 2014-08-01T11:13:10.383
Modified: 2026-06-17T00:11:08.683
Link: CVE-2014-5165
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Debian DSA
EUVD