4.3
CVSSv2

CVE-2015-6242

Published: 24/08/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x prior to 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote malicious users to cause a denial of service (incorrect free operation and application crash) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.3

wireshark wireshark 1.12.4

wireshark wireshark 1.12.5

wireshark wireshark 1.12.0

wireshark wireshark 1.12.2

wireshark wireshark 1.12.1

wireshark wireshark 1.12.6

wireshark wireshark 1.12.3

Vendor Advisories

Multiple vulnerabilities were discovered in the dissectors/parsers for ZigBee, GSM RLC/MAC, WaveAgent, ptvcursor, OpenFlow, WCCP and in internal functions which could result in denial of service For the stable distribution (jessie), these problems have been fixed in version 1121+g01b65bf-4+deb8u3 For the testing distribution (stretch), these pr ...
The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_blockc in the wmem block allocator in the memory manager in Wireshark 112x before 1127 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorr ...