CVE-2015-8733

MEDIUM

Description

The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

References

http://www.debian.org/security/2016/dsa-3505

http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html

http://www.securityfocus.com/bid/79814

http://www.securitytracker.com/id/1034551

http://www.wireshark.org/security/wnpa-sec-2015-51.html

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11827

https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=53a3e53fce30523d11ab3df319fba7b75d63076f

https://security.gentoo.org/glsa/201604-05

Details

Source: MITRE

Published: 2016-01-04

Updated: 2016-12-07

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (8 total)

IDNameProductFamilySeverity
91838F5 Networks BIG-IP : Multiple Wireshark (tshark) vulnerabilities (K01837042)NessusF5 Networks Local Security Checks
high
90744GLSA-201604-05 : Wireshark: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
89695Debian DSA-3505-1 : wireshark - security updateNessusDebian Local Security Checks
medium
87912SUSE SLED11 / SLES11 Security Update : wireshark (SUSE-SU-2016:0110-1)NessusSuSE Local Security Checks
medium
87911SUSE SLED12 / SLES12 Security Update : wireshark (SUSE-SU-2016:0109-1)NessusSuSE Local Security Checks
medium
87833openSUSE Security Update : wireshark (openSUSE-2016-12)NessusSuSE Local Security Checks
medium
87825Wireshark 2.0.0 Multiple DoSNessusWindows
medium
87824Wireshark 1.12.x < 1.12.9 Multiple DoSNessusWindows
medium