VDB
CVE-2015-8733
CVE-2015-8733
PUBLISHED
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
EPSS 1.63% · 82.2th percentile
Risk Scores
EPSS Score
1.63%
82.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | wireshark | 0, 1.10.2-1, 1.10.3-1 |
| Ubuntu:16.04:LTS | wireshark | *, 0, 1.12.7+g7fc8978-1 |
| Ubuntu:18.04:LTS | wireshark | 2.4.3-1, 2.4.4-1, 2.4.5-1 |
Exploit Intelligence
Timeline
- Dec 22, 2015 PoC Published
- Jan 4, 2016 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- https://www.cve.org/CVERecord?id=CVE-2015-8733 third-party-advisory
- https://ubuntu.com/security/CVE-2015-8733 third-party-advisory
- https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=53a3e53fce30523d11ab3df319fba7b75d63076f third-party-advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11827 third-party-advisory
- http://www.wireshark.org/security/wnpa-sec-2015-51.html third-party-advisory