CVE-2015-8736: Input Validation
Published Jan 4, 2016
·Updated
The mp2tfindnextpcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.
Affected Software
1 affected component
Wireshark Wireshark=2.0.0
Event History
Jan 4, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8736?
CVE-2015-8736 is classified as a denial of service vulnerability due to stack-based buffer overflow.
2
How do I fix CVE-2015-8736?
To fix CVE-2015-8736, upgrade to Wireshark version 2.0.1 or later to address the vulnerability.
3
What versions of Wireshark are affected by CVE-2015-8736?
Wireshark version 2.0.0 is affected by CVE-2015-8736.
4
What type of attack does CVE-2015-8736 enable?
CVE-2015-8736 enables remote attackers to execute a denial of service attack, causing application crashes.
5
Where is the vulnerability located in Wireshark related to CVE-2015-8736?
The vulnerability is located in the mp2t_find_next_pcr function of the MP2T file parser in Wireshark.