Wireshark MS-WSP parser DoS Vulnerability (CVE-2015-8742)
Wireshark MS-WSP parser DoS Vulnerability (CVE-2015-8742)
Release date:
Updated on:
Affected Systems:
Wireshark Wireshark 2.0.x-2.0.1
Description:
CVE (CAN) ID: CVE-2015-8742
Wireshark is the most popular network protocol parser.
Wireshark 2.0.x-2.0.1, the function dissect_CPMSetBindings in the epan/dissectors/MS-WSP in the packet-mswsp.c parser does not validate the column size by constructing the packet, remote attackers exploit this vulnerability to cause DoS (memory depletion or application crash ).
<* Source: vendor
*>
Suggestion:
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wireshark.org/security/wnpa-sec-2015-60.html
Https://bugs.wireshark.org/bugzilla/show_bug.cgi? Id = 11931
Https://code.wireshark.org/review/gitweb? P = wireshark. git; a = commit; h = d48b0eff28c995947ac3f8d842ddd9b50dd5798d
Install Wireshark in Ubuntu 13.10
Simple use of Wireshark
Install Wireshark in Ubuntu 12.04
Starting Wireshark packet capture from common users in Linux
Install and run Wireshark in Linux
Wireshark details: click here
Wireshark: click here
This article permanently updates the link address: