The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T08:29:21.395Z
Reserved: 2016-01-03T00:00:00
Link: CVE-2015-8733

No data.

Status : Deferred
Published: 2016-01-04T05:59:23.863
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-8733


No data.