Vulnerabilities
Vulnerable Software
Wireshark:  >> Wireshark  >> 1.12.6  Security Vulnerabilities
The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1) dissector_get_string_handle and (2) dissector_get_default_string_handle functions.
CVSS Score
4.3
EPSS Score
0.007
Published
2015-08-24
The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect free operation and application crash) via a crafted packet.
CVSS Score
4.3
EPSS Score
0.006
Published
2015-08-24
The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CVSS Score
4.3
EPSS Score
0.006
Published
2015-08-24


Contact Us

Shodan ® - All rights reserved