CVE-2015-3182Improper Input Validation in Wireshark

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 75.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 4
Latest updateMay 17

Description

epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.12.0~rc1-1 (bookworm)
Debianwireshark/wireshark< 1.12.0~rc1-1+3
NVDwireshark/wireshark1.10.12, 1.10.13, 1.10.14+2

🔴Vulnerability Details

2
GHSA
GHSA-p39p-p27m-9c4h: epan/dissectors/packet-dec-dnart2022-05-17
OSV
CVE-2015-3182: epan/dissectors/packet-dec-dnart2016-01-04

📋Vendor Advisories

2
Red Hat
wireshark: crash on sample file genbroad.snoop2015-05-07
Debian
CVE-2015-3182: wireshark - epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1...2015

💬Community

2
Bugzilla
CVE-2015-3182 wireshark: crash on sample file genbroad.snoop2015-05-07
Bugzilla
CVE-2015-0562 wireshark: DEC DNA Routing Protocol dissector crash (wnpa-sec-2015-03)2015-01-08