CVE-2015-0564
published 2015-01-10CVE-2015-0564: Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.77%
84.8th percentile
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 1.12.1+g01b65bf-3 (bookworm) | wireshark 1.12.1+g01b65bf-3 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | linux | — | — |
| oracle | solaris | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.12.1+g01b65bf-3 | 1.12.1+g01b65bf-3 |
| wireshark | wireshark | >= 0 < 1.12.1+g01b65bf-3 | 1.12.1+g01b65bf-3 |
| wireshark | wireshark | >= 0 < 1.12.1+g01b65bf-3 | 1.12.1+g01b65bf-3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
vendor_redhat·2015-01-07·CVSS 5.0
CVE-2015-0564 [MEDIUM] CWE-131 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
Statement: This issue affects the verison of wireshark as shipped with Red Hat Enterprsie Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates.
Package: wireshark (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-0564: wireshark - Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ss...
vendor_debian·2015·CVSS 5.0
CVE-2015-0564 [MEDIUM] CVE-2015-0564: wireshark - Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ss...
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
Scope: local
bookworm: resolved (fixed in 1.12.1+g01b65bf-3)
bullseye: resolved (fixed in 1.12.1+g01b65bf-3)
forky: resolved (fixed in 1.12.1+g01b65bf-3)
sid: resolved (fixed in 1.12.1+g01b65bf-3)
trixie: resolved (fixed in 1.12.1+g01b65bf-3)
GHSA
GHSA-wmjp-f22x-624h: Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils
ghsa_unreviewed·2022-05-13
CVE-2015-0564 [MEDIUM] CWE-119 GHSA-wmjp-f22x-624h: Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
OSV
CVE-2015-0564: Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils
osv·2015-01-10·CVSS 5.0
CVE-2015-0564 [MEDIUM] CVE-2015-0564: Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0564 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05) [fedora-all]
bugzilla·2015-01-08·CVSS 5.0
CVE-2015-0564 [MEDIUM] CVE-2015-0564 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05) [fedora-all]
CVE-2015-0564 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-0564 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
bugzilla·2015-01-08·CVSS 5.0
CVE-2015-0564 [MEDIUM] CVE-2015-0564 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
CVE-2015-0564 wireshark: TLS/SSL decryption crash (wnpa-sec-2015-05)
A buffer underflow flaw was found in the way Wireshark decypted TLS/SSL sessions. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
This is reported to affect Wireshark versions 1.12.0 to 1.12.2, and 1.10.0 to 1.10.11. It is fixed in versions 1.12.3 and 1.10.12.
External References:
https://www.wireshark.org/security/wnpa-sec-2015-05.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1180198]
---
upstream fix
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commitdiff;h=d3581aecda62d2a51ea7088fd46975415b03ec57;hp=ac52f0e6bf020fd9b12f603bdb6e90a469bceed8
---
Ana
http://advisories.mageia.org/MGASA-2015-0019.htmlhttp://lists.opensuse.org/opensuse-updates/2015-01/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1460.htmlhttp://secunia.com/advisories/62612http://secunia.com/advisories/62673http://www.debian.org/security/2015/dsa-3141http://www.mandriva.com/security/advisories?name=MDVSA-2015:022http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71922http://www.wireshark.org/security/wnpa-sec-2015-05.htmlhttps://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=d3581aecda62d2a51ea7088fd46975415b03ec57http://advisories.mageia.org/MGASA-2015-0019.htmlhttp://lists.opensuse.org/opensuse-updates/2015-01/msg00053.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1460.htmlhttp://secunia.com/advisories/62612http://secunia.com/advisories/62673http://www.debian.org/security/2015/dsa-3141http://www.mandriva.com/security/advisories?name=MDVSA-2015:022http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71922http://www.wireshark.org/security/wnpa-sec-2015-05.htmlhttps://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=d3581aecda62d2a51ea7088fd46975415b03ec57
2015-01-10
Published