CVE-2015-8726: Buffer Overflow
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation and Coding Scheme (MCS) data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8726?
The severity of CVE-2015-8726 is classified as high due to its potential for crashing the application.
How do I fix CVE-2015-8726?
To fix CVE-2015-8726, upgrade Wireshark to version 1.12.9 or 2.0.1 or later.
What versions of Wireshark are affected by CVE-2015-8726?
CVE-2015-8726 affects Wireshark versions 1.12.0 to 1.12.8 and 2.0.0.
What type of exploit is associated with CVE-2015-8726?
CVE-2015-8726 is associated with a denial of service exploit resulting from an out-of-bounds read.
Can I continue using affected versions of Wireshark despite CVE-2015-8726?
It is not recommended to continue using affected versions of Wireshark as they are vulnerable to crashes.