CVE-2015-4651
published 2015-07-22CVE-2015-4651: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.52%
88.0th percentile
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 1.12.6+gee1fce6-1 (bookworm) | wireshark 1.12.6+gee1fce6-1 (bookworm) |
| oracle | solaris | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.12.6+gee1fce6-1 | 1.12.6+gee1fce6-1 |
| wireshark | wireshark | >= 0 < 1.12.6+gee1fce6-1 | 1.12.6+gee1fce6-1 |
| wireshark | wireshark | >= 0 < 1.12.6+gee1fce6-1 | 1.12.6+gee1fce6-1 |
| wireshark | wireshark | >= 0 < 1.12.6+gee1fce6-1 | 1.12.6+gee1fce6-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wmj6-6646-26fx: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp
ghsa_unreviewed·2022-05-17
CVE-2015-4651 [MEDIUM] GHSA-wmj6-6646-26fx: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
OSV
CVE-2015-4651: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp
osv·2015-07-22·CVSS 5.0
CVE-2015-4651 [MEDIUM] CVE-2015-4651: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Red Hat
wireshark: WCCP dissector crash (wnpa-sec-2015-19)
vendor_redhat·2015-06-17·CVSS 5.0
CVE-2015-4651 [MEDIUM] wireshark: WCCP dissector crash (wnpa-sec-2015-19)
wireshark: WCCP dissector crash (wnpa-sec-2015-19)
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Package: wireshark (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-4651: wireshark - The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c...
vendor_debian·2015·CVSS 5.0
CVE-2015-4651 [MEDIUM] CVE-2015-4651: wireshark - The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c...
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.12.6+gee1fce6-1)
bullseye: resolved (fixed in 1.12.6+gee1fce6-1)
forky: resolved (fixed in 1.12.6+gee1fce6-1)
sid: resolved (fixed in 1.12.6+gee1fce6-1)
trixie: resolved (fixed in 1.12.6+gee1fce6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4651 wireshark: WCCP dissector crash (wnpa-sec-2015-19)
bugzilla·2015-06-22·CVSS 5.0
CVE-2015-4651 [MEDIUM] CVE-2015-4651 wireshark: WCCP dissector crash (wnpa-sec-2015-19)
CVE-2015-4651 wireshark: WCCP dissector crash (wnpa-sec-2015-19)
It was reported that it may be possible to make Wireshark crash by injecting a malformed WCCP packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11153
Upstream commit: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=524ed1df6e6126cd63ba419ccb82c83636d77ee4
External References:
https://www.wireshark.org/security/wnpa-sec-2015-19.html
Statement:
This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1234417]
Bugzilla
CVE-2014-4651 JClouds: predictable tmp file creation in ScriptBuilder Statements
bugzilla·2014-06-24·CVSS 9.8
CVE-2014-4651 [CRITICAL] CVE-2014-4651 JClouds: predictable tmp file creation in ScriptBuilder Statements
CVE-2014-4651 JClouds: predictable tmp file creation in ScriptBuilder Statements
JClouds scriptbuilder Statements.java writes a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, denial of service, or other attacks.
http://seclists.org/oss-sec/2014/q2/579
https://issues.apache.org/jira/browse/JCLOUDS-612
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Fuse 6.2.0
Via RHSA-2015:1176 https://rhn.redhat.com/errata/RHSA-2015-1176.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00020.htmlhttp://www.debian.org/security/2015/dsa-3294http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/75317http://www.securitytracker.com/id/1032662http://www.wireshark.org/security/wnpa-sec-2015-19.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11153https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=524ed1df6e6126cd63ba419ccb82c83636d77ee4https://security.gentoo.org/glsa/201510-03http://lists.opensuse.org/opensuse-updates/2015-07/msg00020.htmlhttp://www.debian.org/security/2015/dsa-3294http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/75317http://www.securitytracker.com/id/1032662http://www.wireshark.org/security/wnpa-sec-2015-19.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11153https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=524ed1df6e6126cd63ba419ccb82c83636d77ee4https://security.gentoo.org/glsa/201510-03
2015-07-22
Published