CVE-2015-8733: Input Validation
Published Jan 4, 2016
·Updated
The ngsnifferprocessrecord function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Affected Software
10 affected components
Wireshark Wireshark=1.12.0
Wireshark Wireshark=1.12.1
Wireshark Wireshark=1.12.2
Wireshark Wireshark=1.12.3
Wireshark Wireshark=1.12.4
Wireshark Wireshark=1.12.5
Wireshark Wireshark=1.12.6
Wireshark Wireshark=1.12.7
Wireshark Wireshark=1.12.8
Wireshark Wireshark=2.0.0
Event History
Jan 4, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8733?
CVE-2015-8733 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2015-8733?
To fix CVE-2015-8733, you should upgrade to Wireshark version 1.12.9 or 2.0.1 or later.
3
What versions of Wireshark are affected by CVE-2015-8733?
CVE-2015-8733 affects Wireshark versions 1.12.0 through 1.12.8 and 2.0.0.
4
What impact does CVE-2015-8733 have on Wireshark performance?
CVE-2015-8733 can lead to a denial of service, potentially crashing the application.
5
Is CVE-2015-8733 exploitable remotely?
Yes, CVE-2015-8733 can be exploited by remote attackers to cause denial of service.