CVE-2015-8723
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote…
Does this matter?
Lower severity and a low EPSS score (4.69%). Track it; it rarely justifies an emergency change on its own.
Description
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 4.69% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-119
- Affected
- wireshark/wireshark
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2016/dsa-3505
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/79382
- http://www.securitytracker.com/id/1034551
- http://www.wireshark.org/security/wnpa-sec-2015-42.htmlVendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11790
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=40b283181c63cb28bc6f58d80315eccca6650da0
- https://security.gentoo.org/glsa/201604-05
- http://www.debian.org/security/2016/dsa-3505
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/79382
- http://www.securitytracker.com/id/1034551
- http://www.wireshark.org/security/wnpa-sec-2015-42.htmlVendor Advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11790
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=40b283181c63cb28bc6f58d80315eccca6650da0
- https://security.gentoo.org/glsa/201604-05
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.