CVE-2015-8730
MEDIUMWireshark 1.12.x < 1.12.9 and 2.0.x < 2.0.1 - Denial of Service in NBAP Dissector
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-8730. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in Wireshark due to an invalid memory read in the NBAP dissector. The crash occurs when processing a malformed packet capture file, leading to a SIGSEGV in the `dissect_nbap_MACdPDU_Size` function.
Description
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted packet.
Exploits (1)
This exploit demonstrates a denial-of-service (DoS) vulnerability in Wireshark due to an invalid memory read in the NBAP dissector. The crash occurs when processing a malformed packet capture file, leading to a SIGSEGV in the `dissect_nbap_MACdPDU_Size` function.
References (8)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H