CVE-2015-0560
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not initialize certain data structures, which allows remote attackers to cause a…
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not initialize certain data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- wireshark/wireshark · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00053.html
- http://secunia.com/advisories/62612
- http://www.wireshark.org/security/wnpa-sec-2015-01.htmlVendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10806
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=a442a1c0e815fd61416cf408bd74d85a042ccc6a
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00053.html
- http://secunia.com/advisories/62612
- http://www.wireshark.org/security/wnpa-sec-2015-01.htmlVendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10806
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=a442a1c0e815fd61416cf408bd74d85a042ccc6a
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.