UBUNTU-CVE-2015-8726
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-8726
Summary:
Details: wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation and Coding Scheme (MCS) data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
References: https://ubuntu.com/security/CVE-2015-8726, https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b8fa3d463c1bdd9b84c897441e7a5c8ad1f0f292, https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=185911de7d337246044c8e99da2f5b4bac74c0d5, https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11791, https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11789, http://www.wireshark.org/security/wnpa-sec-2015-44.html, https://www.cve.org/CVERecord?id=CVE-2015-8726
Affected packages
Package
Name: wireshark
Purl: pkg:deb/ubuntu/[email protected]~ubuntu14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
