Wireshark 1.6.x < 1.6.13 Multiple Vulnerabilities (macOS)

high Nessus Plugin ID 363835

Synopsis

An application installed on the remote macOS / Mac OS X host is affected by multiple vulnerabilities.

Description

The version of Wireshark installed on the remote macOS / Mac OS X host is prior to 1.6.13. It is, therefore, affected by multiple vulnerabilities as referenced in the wireshark-1.6.13 advisory.

- Buffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet. (CVE-2013-1590)

- The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle certain short lengths, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. (CVE-2013-1572)

- The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a large number of padding bits, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. (CVE-2013-1573)

- The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in the Bluetooth HCI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a counter variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. (CVE-2013-1574)

- The dissect_r3_cmd_alarmconfigure function in epan/dissectors/packet-assa_r3.c in the R3 dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle a certain alarm length, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.
(CVE-2013-1575)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Wireshark version 1.6.13 or later.

See Also

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7871

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7945

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8036

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8037

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8038

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8040

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8041

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8042

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8043

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8111

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8112

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8197

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8198

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8199

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8213

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8222

https://www.wireshark.org/docs/relnotes/wireshark-1.6.13.html

https://www.wireshark.org/security/wnpa-sec-2013-01

https://www.wireshark.org/security/wnpa-sec-2013-02

https://www.wireshark.org/security/wnpa-sec-2013-03

https://www.wireshark.org/security/wnpa-sec-2013-04

https://www.wireshark.org/security/wnpa-sec-2013-05

https://www.wireshark.org/security/wnpa-sec-2013-07

https://www.wireshark.org/security/wnpa-sec-2013-08

https://www.wireshark.org/security/wnpa-sec-2013-09

Plugin Details

Severity: High

ID: 363835

File Name: macosx_wireshark_1_6_13.nasl

Version: 1.1

Type: Local

Agent: macosx

Published: 10/7/2026

Updated: 10/7/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Low

Base Score: 2.9

Temporal Score: 2.1

Vector: CVSS2#AV:A/AC:M/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2013-1590

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:wireshark:wireshark

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, installed_sw/Wireshark

Exploit Ease: No known exploits are available

Patch Publication Date: 1/29/2013

Vulnerability Publication Date: 1/29/2013

Reference Information

CVE: CVE-2013-1572, CVE-2013-1573, CVE-2013-1574, CVE-2013-1575, CVE-2013-1576, CVE-2013-1577, CVE-2013-1578, CVE-2013-1579, CVE-2013-1580, CVE-2013-1581, CVE-2013-1582, CVE-2013-1583, CVE-2013-1584, CVE-2013-1585, CVE-2013-1586, CVE-2013-1588, CVE-2013-1589, CVE-2013-1590

IAVB: 2013-B-0009-S