4.3
CVSSv2

CVE-2015-6241

Published: 24/08/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x prior to 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote malicious users to cause a denial of service (application crash) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 1.12.4

wireshark wireshark 1.12.5

wireshark wireshark 1.12.0

wireshark wireshark 1.12.2

wireshark wireshark 1.12.1

wireshark wireshark 1.12.6

wireshark wireshark 1.12.3

oracle solaris 11.3

Vendor Advisories

Multiple vulnerabilities were discovered in the dissectors/parsers for ZigBee, GSM RLC/MAC, WaveAgent, ptvcursor, OpenFlow, WCCP and in internal functions which could result in denial of service For the stable distribution (jessie), these problems have been fixed in version 1121+g01b65bf-4+deb8u3 For the testing distribution (stretch), these pr ...
The proto_tree_add_bytes_item function in epan/protoc in the protocol-tree implementation in Wireshark 112x before 1127 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet ...