Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3811

Опубликовано: 26 мая 2015
Источник: debian
EPSS Низкий

Описание

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wiresharkfixed1.12.5+g5819e5b-1package
wiresharkfixed1.8.2-5wheezy16wheezypackage

Примечания

  • add fixed version for wheezy directly in CVE list since CVE-2015-3811 the only fixed in DSA-3277-1

  • https://www.wireshark.org/security/wnpa-sec-2015-14.html

  • https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10978

  • https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a6fc6aa0b4efc1a1c3d7a2e3b5189e888fb6ccc2

EPSS

Процентиль: 44%
0.00212
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

redhat
больше 10 лет назад

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

nvd
больше 10 лет назад

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

github
больше 3 лет назад

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

suse-cvrf
около 10 лет назад

Security update for wireshark

EPSS

Процентиль: 44%
0.00212
Низкий