First published: Mon Jan 04 2016(Updated: )
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8740 has a high severity due to its potential to cause a denial of service through a buffer overflow.
To fix CVE-2015-8740, upgrade to Wireshark version 2.0.1 or later.
Attackers can exploit CVE-2015-8740 to crash the Wireshark application, leading to a denial of service.
CVE-2015-8740 affects Wireshark version 2.0.0.
CVE-2015-8740 is a remote vulnerability that can be exploited through crafted packets.