CVE-2015-8728: Input Validation
The Mobile Identity parser in (1) epan/dissectors/packet-ansia.c in the ANSI A dissector and (2) epan/dissectors/packet-gsmacommon.c in the GSM A dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly uses the tvbbcddigtowmempacketstr function, which allows remote attackers to cause a denial of service (buffer overflow and application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8728?
CVE-2015-8728 is rated as a medium severity vulnerability, potentially allowing remote attackers to cause denial of service.
How do I fix CVE-2015-8728?
To mitigate CVE-2015-8728, update Wireshark to version 1.12.9 or higher for the 1.12.x branch or 2.0.1 or higher for the 2.0.x branch.
What versions of Wireshark are affected by CVE-2015-8728?
CVE-2015-8728 affects Wireshark versions 1.12.0 to 1.12.8 and 2.0.0.
Is CVE-2015-8728 exploitable over a network?
Yes, CVE-2015-8728 can be exploited remotely, making it a critical concern for network security.
What are the implications of CVE-2015-8728 for Wireshark users?
Users of vulnerable Wireshark versions may experience crashes or denial of service when processing malicious packets.