PT-2015-5651 · Wireshark+4 · Wireshark+4

Gerald Combs

·

Published

2015-03-06

·

Updated

2024-06-15

·

CVE-2015-2189

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.10.x through 1.10.12 Wireshark versions 1.12.x through 1.12.3
Description The issue is caused by an off-by-one error in the pcapng read function in the pcapng file parser. This error allows remote attackers to cause a denial of service, resulting in an out-of-bounds read and application crash, by sending a crafted packet with an invalid Interface Statistics Block (ISB) interface ID.
Recommendations For Wireshark versions 1.10.x through 1.10.12, update to version 1.10.13 or later. For Wireshark versions 1.12.x through 1.12.3, update to version 1.12.4 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1264
CESA-2015_1460
CESA-2015_2393
CVE-2015-2189
DSA-3210-1
MGASA-2015-0117
OPENSUSE-SU-2024:10199-1
RHSA-2015:1460
RHSA-2015:2393
RHSA-2015_1460
RHSA-2015_2393
SUSE-SU-2015:0426-1
SUSE-SU-2015:0653-1
SUSE-SU-2015:0657-1
SUSE-SU-2015:0657-2
SUSE-SU-2015:1098-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Wireshark