CVE-2015-3811Improper Initialization in Wireshark

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 59.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 13

Description

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Debianwireshark/wireshark< 1.12.5+g5819e5b-1+3
NVDwireshark/wireshark19 versions+18
NVDoracle/solaris11.2

🔴Vulnerability Details

3
GHSA
GHSA-4669-mhpf-8vf3: epan/dissectors/packet-wcp2022-05-13
CVEList
CVE-2015-3811: epan/dissectors/packet-wcp2015-05-26
OSV
CVE-2015-3811: epan/dissectors/packet-wcp2015-05-26

📋Vendor Advisories

2
Red Hat
wireshark: WCP dissector crash (wnpa-sec-2015-14)2015-05-12
Debian
CVE-2015-3811: wireshark - epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.1...2015

💬Community

1
Bugzilla
CVE-2015-3811 wireshark: WCP dissector crash (wnpa-sec-2015-14)2015-05-18
CVE-2015-3811 — Improper Initialization in Wireshark | cvebase