CVE-2015-8733

MEDIUM

Wireshark - Improper Input Validation

Title source: rule

Description

The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/39076

Scores

CVSS v3 5.5
EPSS 0.0163
EPSS Percentile 81.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-20
Status draft

Affected Products (10)

wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark
wireshark/wireshark

Timeline

Published Jan 04, 2016
Tracked Since Feb 18, 2026