4.3
CVSSv2

CVE-2015-6249

Published: 24/08/2015 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x prior to 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote malicious users to cause a denial of service (application crash) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.3

wireshark wireshark 1.12.4

wireshark wireshark 1.12.5

wireshark wireshark 1.12.0

wireshark wireshark 1.12.2

wireshark wireshark 1.12.1

wireshark wireshark 1.12.6

wireshark wireshark 1.12.3

Vendor Advisories

Multiple vulnerabilities were discovered in the dissectors/parsers for ZigBee, GSM RLC/MAC, WaveAgent, ptvcursor, OpenFlow, WCCP and in internal functions which could result in denial of service For the stable distribution (jessie), these problems have been fixed in version 1121+g01b65bf-4+deb8u3 For the testing distribution (stretch), these pr ...
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccpc in the WCCP dissector in Wireshark 112x before 1127 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet ...