VYPR
Medium severity5.5NVD Advisory· Published Jan 4, 2016· Updated May 6, 2026

CVE-2015-8733

CVE-2015-8733

Description

The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

Affected products

10
  • Wireshark/Wireshark10 versions
    cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:1.12.8:*:*:*:*:*:*:*
    • cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.