Description
The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remote attackers to cause a denial of service (stack memory corruption and application crash) via a crafted packet.
References (7)
Core 7
Core References
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-03/msg00038.html
Vendor Advisory x_refsource_confirm
http://www.wireshark.org/security/wnpa-sec-2015-06.html
Issue Tracking x_refsource_confirm
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9952
Patch x_refsource_confirm
https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=1a3dd349233a4ee3e69295c8e79f9a216027037e
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031858
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201510-03
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72940
Scores
EPSS
0.0033
EPSS Percentile
56.0%
Details
CWE
CWE-20
Status
published
Products (6)
opensuse/opensuse
13.1
opensuse/opensuse
13.2
wireshark/wireshark
1.12.0
wireshark/wireshark
1.12.1
wireshark/wireshark
1.12.2
wireshark/wireshark
1.12.3
Published
Mar 08, 2015
Tracked Since
Feb 18, 2026