CVE-2015-3808: High severity wireshark vulnerability
Published May 26, 2015
·Updated
The dissectlbmrpser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not reject a zero length, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Affected Software
5 affected components
Wireshark Wireshark=1.12.0
Wireshark Wireshark=1.12.1
Wireshark Wireshark=1.12.2
Wireshark Wireshark=1.12.3
Wireshark Wireshark=1.12.4
Event History
May 26, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3808?
CVE-2015-3808 has a severity rating that indicates it can lead to a denial of service.
2
How do I fix CVE-2015-3808?
To fix CVE-2015-3808, update Wireshark to version 1.12.5 or later.
3
What does CVE-2015-3808 affect?
CVE-2015-3808 affects Wireshark versions 1.12.0 to 1.12.4.
4
What is the impact of CVE-2015-3808?
The impact of CVE-2015-3808 is the potential for an infinite loop leading to service interruption.
5
Who exploits CVE-2015-3808?
CVE-2015-3808 can be exploited by remote attackers using specially crafted packets.