PT-2015-6333 · Wireshark+4 · Wireshark+4

Published

2015-05-12

·

Updated

2024-06-15

·

CVE-2015-3813

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.12.x through 1.12.4
Description The issue is related to the packet-reassembly feature in Wireshark. It allows remote attackers to cause a denial of service, specifically memory consumption, via a crafted packet. This occurs due to the fragment add work function not properly determining the defragmentation state when the snapshot length is insufficient.
Recommendations For Wireshark versions 1.12.x through 1.12.4, update to version 1.12.5 or later to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1462
CESA-2015_2393
CESA-2017_0631
CVE-2015-3813
DSA-3277-1
OPENSUSE-SU-2024:10199-1
RHSA-2015:2393
RHSA-2015_2393
RHSA-2017:0631
RHSA-2017_0631
SUSE-SU-2015:1046-1
SUSE-SU-2015:1676-1
SUSE-SU-2015:1676-2
SUSE-SU-2015:1713-1
SUSE-SU-2015_1676-1
SUSE-SU-2015_1676-2
SUSE-SU-2015_1713-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Wireshark