CVE-2015-4651
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote…
Does this matter?
Lower severity and a low EPSS score (3.52%). Track it; it rarely justifies an emergency change on its own.
Description
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.52% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- wireshark/wireshark · debian/debian linux · oracle/solaris
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2015-07/msg00020.html
- http://www.debian.org/security/2015/dsa-3294Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlThird Party Advisory
- http://www.securityfocus.com/bid/75317
- http://www.securitytracker.com/id/1032662
- http://www.wireshark.org/security/wnpa-sec-2015-19.htmlVendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11153Issue Tracking
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=524ed1df6e6126cd63ba419ccb82c83636d77ee4
- https://security.gentoo.org/glsa/201510-03
- http://lists.opensuse.org/opensuse-updates/2015-07/msg00020.html
- http://www.debian.org/security/2015/dsa-3294Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlThird Party Advisory
- http://www.securityfocus.com/bid/75317
- http://www.securitytracker.com/id/1032662
- http://www.wireshark.org/security/wnpa-sec-2015-19.htmlVendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11153Issue Tracking
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=524ed1df6e6126cd63ba419ccb82c83636d77ee4
- https://security.gentoo.org/glsa/201510-03
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.