CVE Vulnerabilities

CVE-2015-0560

Published: Jan 10, 2015 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not initialize certain data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 1.10.0 (including) 1.10.0 (including)
Wireshark Wireshark 1.10.1 (including) 1.10.1 (including)
Wireshark Wireshark 1.10.2 (including) 1.10.2 (including)
Wireshark Wireshark 1.10.3 (including) 1.10.3 (including)
Wireshark Wireshark 1.10.4 (including) 1.10.4 (including)
Wireshark Wireshark 1.10.5 (including) 1.10.5 (including)
Wireshark Wireshark 1.10.6 (including) 1.10.6 (including)
Wireshark Wireshark 1.10.7 (including) 1.10.7 (including)
Wireshark Wireshark 1.10.8 (including) 1.10.8 (including)
Wireshark Wireshark 1.10.9 (including) 1.10.9 (including)
Wireshark Wireshark 1.10.10 (including) 1.10.10 (including)
Wireshark Wireshark 1.10.11 (including) 1.10.11 (including)
Wireshark Wireshark 1.12.0 (including) 1.12.0 (including)
Wireshark Wireshark 1.12.1 (including) 1.12.1 (including)
Wireshark Wireshark 1.12.2 (including) 1.12.2 (including)
Wireshark Ubuntu artful *
Wireshark Ubuntu bionic *
Wireshark Ubuntu lucid *
Wireshark Ubuntu precise *
Wireshark Ubuntu trusty *
Wireshark Ubuntu upstream *
Wireshark Ubuntu utopic *
Wireshark Ubuntu vivid *
Wireshark Ubuntu wily *
Wireshark Ubuntu xenial *
Wireshark Ubuntu yakkety *
Wireshark Ubuntu zesty *

References