CVE-2015-6241: Input Validation
The prototreeaddbytesitem function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6241?
CVE-2015-6241 has a severity rating that indicates it can lead to denial of service due to application crashes.
How do I fix CVE-2015-6241?
To fix CVE-2015-6241, upgrade Wireshark to version 1.12.7 or later.
Which versions of Wireshark are affected by CVE-2015-6241?
CVE-2015-6241 affects Wireshark versions 1.12.0 through 1.12.6.
Can CVE-2015-6241 be exploited remotely?
Yes, CVE-2015-6241 can be exploited by remote attackers, potentially causing application crashes.
What type of vulnerability is CVE-2015-6241?
CVE-2015-6241 is a denial of service vulnerability found in the protocol-tree implementation of Wireshark.