VDB
CVE-2015-8733
CVE-2015-8733
PUBLISHED
CVSS 5.5 MEDIUM
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
EPSS 4.15% · 90.5th percentile
Risk Scores
CVSS 3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
4.15%
90.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | wireshark | 0, 1.10.2-1, 1.10.3-1 |
| Ubuntu:16.04:LTS | wireshark | *, 0, 1.12.7+g7fc8978-1 |
| Ubuntu:18.04:LTS | wireshark | 2.4.3-1, 2.4.4-1, 2.4.5-1 |
Timeline
- Dec 22, 2015 PoC Published
- Jan 4, 2016 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
- Sep 11, 2023 EPSS Score
References
- https://www.cve.org/CVERecord?id=CVE-2015-8733 third-party-advisory
- https://ubuntu.com/security/CVE-2015-8733 third-party-advisory
- https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=53a3e53fce30523d11ab3df319fba7b75d63076f third-party-advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11827 third-party-advisory
- http://www.wireshark.org/security/wnpa-sec-2015-51.html third-party-advisory