CVE-2013-4074
Wireshark - Numeric Error
Title source: ruleDescription
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Exploits (2)
metasploit
WORKING POC
by Laurent Butti, j0sm1 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/wireshark/capwap.rb
References (17)
Scores
EPSS
0.3246
EPSS Percentile
96.9%
Details
CWE
CWE-189
Status
published
Products (28)
debian/debian_linux
7.0
opensuse/opensuse
11.4
opensuse/opensuse
12.2
opensuse/opensuse
12.3
wireshark/wireshark
1.6.0
wireshark/wireshark
1.6.1
wireshark/wireshark
1.6.2
wireshark/wireshark
1.6.3
wireshark/wireshark
1.6.4
wireshark/wireshark
1.6.5
... and 18 more
Published
Jun 09, 2013
Tracked Since
Feb 18, 2026