4.3
CVSSv2

CVE-2015-6247

Published: 24/08/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x prior to 1.12.7 does not validate a certain offset value, which allows remote malicious users to cause a denial of service (infinite loop) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.3

wireshark wireshark 1.12.4

wireshark wireshark 1.12.5

wireshark wireshark 1.12.0

wireshark wireshark 1.12.2

wireshark wireshark 1.12.1

wireshark wireshark 1.12.6

wireshark wireshark 1.12.3

Vendor Advisories

Multiple vulnerabilities were discovered in the dissectors/parsers for ZigBee, GSM RLC/MAC, WaveAgent, ptvcursor, OpenFlow, WCCP and in internal functions which could result in denial of service For the stable distribution (jessie), these problems have been fixed in version 1121+g01b65bf-4+deb8u3 For the testing distribution (stretch), these pr ...
The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5c in the OpenFlow dissector in Wireshark 112x before 1127 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet ...