wnpa-sec-2013-66 · SIP dissector infinite loop


Name: SIP dissector infinite loop

Docid: wnpa-sec-2013-66

Date: December 17, 2013

Affected versions: 1.10.0 to 1.10.3, 1.8.0 to 1.8.11

Fixed versions: 1.10.4, 1.8.12

Wireshark bug 9388



The SIP dissector could go into an infinite loop. Discovered by Alain Botti.


It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.


Upgrade to Wireshark 1.10.4, 1.8.12 or later.

Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE $29.95/yr
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
  • • Fully integrated with Wireshark and AirPcap™
Buy $29.95 Annual Subscription Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More

I need to capture wireless traffic...

ANSWER: AirPcap™ 802.11 Packet Capture
  • • WLAN packet capture and transmission
  • • Full 802.11 a/b/g/n support
  • • View management, control and data frames
  • • Multi-channel aggregation (with multiple adapters)
Learn More Buy Now