First published: Tue May 26 2015(Updated: )
The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not properly track the current offset, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =1.12.0 | |
Wireshark Wireshark | =1.12.1 | |
Wireshark Wireshark | =1.12.2 | |
Wireshark Wireshark | =1.12.3 | |
Wireshark Wireshark | =1.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3809 is rated as a moderate severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2015-3809, upgrade to Wireshark version 1.12.5 or later.
CVE-2015-3809 affects Wireshark versions 1.12.0 through 1.12.4.
CVE-2015-3809 is a denial-of-service vulnerability due to improper offset tracking in the LBMR dissector.
Yes, CVE-2015-3809 can be exploited by remote attackers using crafted packets.