CVE-2015-8733

The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.5:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.6:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.7:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.12.8:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:39

Type Values Removed Values Added
References () http://www.debian.org/security/2016/dsa-3505 - () http://www.debian.org/security/2016/dsa-3505 -
References () http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html - () http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html -
References () http://www.securityfocus.com/bid/79814 - () http://www.securityfocus.com/bid/79814 -
References () http://www.securitytracker.com/id/1034551 - () http://www.securitytracker.com/id/1034551 -
References () http://www.wireshark.org/security/wnpa-sec-2015-51.html - Vendor Advisory () http://www.wireshark.org/security/wnpa-sec-2015-51.html - Vendor Advisory
References () https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11827 - () https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11827 -
References () https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=53a3e53fce30523d11ab3df319fba7b75d63076f - () https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=53a3e53fce30523d11ab3df319fba7b75d63076f -
References () https://security.gentoo.org/glsa/201604-05 - () https://security.gentoo.org/glsa/201604-05 -

07 Nov 2023, 02:28

Type Values Removed Values Added
References
  • {'url': 'https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=53a3e53fce30523d11ab3df319fba7b75d63076f', 'name': 'https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=53a3e53fce30523d11ab3df319fba7b75d63076f', 'tags': [], 'refsource': 'CONFIRM'}
  • () https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=53a3e53fce30523d11ab3df319fba7b75d63076f -

Information

Published : 2016-01-04 05:59

Updated : 2025-04-12 10:46


NVD link : CVE-2015-8733

Mitre link : CVE-2015-8733

CVE.ORG link : CVE-2015-8733


JSON object : View

Products Affected

wireshark

  • wireshark
CWE
CWE-20

Improper Input Validation