CVE-2015-8723: Buffer Overflow
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8723?
CVE-2015-8723 has a severity rating that classifies it as potentially critical due to its ability to cause a denial of service.
How do I fix CVE-2015-8723?
To fix CVE-2015-8723, users should upgrade to Wireshark version 1.12.9 or 2.0.1 or later.
What versions of Wireshark are affected by CVE-2015-8723?
CVE-2015-8723 affects Wireshark versions 1.12.0 to 1.12.8 and 2.0.0 to 2.0.0.
What is the impact of CVE-2015-8723 on users?
The impact of CVE-2015-8723 on users includes a potential crash of the Wireshark application due to stack-based buffer overflow.
Can CVE-2015-8723 be exploited remotely?
Yes, CVE-2015-8723 can be exploited remotely by attackers sending crafted packets to the Wireshark application.