CVE-2015-8721: Input Validation
Buffer overflow in the tvbuncompress function in epan/tvbuffzlib.c in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet with zlib compression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8721?
CVE-2015-8721 has a severity rating that could lead to a denial of service due to a buffer overflow vulnerability.
How do I fix CVE-2015-8721?
To fix CVE-2015-8721, you should update Wireshark to version 1.12.9 or later for the 1.12.x series, or version 2.0.1 or later for the 2.0.x series.
Which versions of Wireshark are affected by CVE-2015-8721?
Wireshark versions 1.12.0 to 1.12.8 and 2.0.0 are affected by CVE-2015-8721.
What types of attacks could exploit CVE-2015-8721?
CVE-2015-8721 can be exploited by remote attackers through crafted packets with zlib compression to cause application crashes.
What component of Wireshark is impacted by CVE-2015-8721?
CVE-2015-8721 impacts the tvb_uncompress function in the epan/tvbuff_zlib.c file of Wireshark.