CVE-2015-6242: Input Validation
The wmemblocksplitfreechunk function in epan/wmem/wmemallocatorblock.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect free operation and application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6242?
CVE-2015-6242 is classified as a medium severity vulnerability.
How do I fix CVE-2015-6242?
To resolve CVE-2015-6242, upgrade Wireshark to version 1.12.7 or later.
Which versions of Wireshark are affected by CVE-2015-6242?
Wireshark versions 1.12.0 through 1.12.6 are affected by CVE-2015-6242.
What type of vulnerability is CVE-2015-6242?
CVE-2015-6242 is a memory management vulnerability that can lead to heap corruption.
Is CVE-2015-6242 specific to any operating system?
CVE-2015-6242 primarily affects Wireshark, but it is also noted in contexts involving Oracle Solaris and ZFS.