CVE-2015-2189: Medium severity wireshark vulnerability
Off-by-one error in the pcapngread function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2189?
CVE-2015-2189 is considered to have a high severity rating due to its potential for causing denial of service through application crashes.
How do I fix CVE-2015-2189?
To fix CVE-2015-2189, upgrade Wireshark to version 1.10.13 or later for the 1.10.x series and version 1.12.4 or later for the 1.12.x series.
What versions of Wireshark are affected by CVE-2015-2189?
Wireshark versions 1.10.0 to 1.10.12 and 1.12.0 to 1.12.3 are affected by CVE-2015-2189.
What is the cause of the vulnerability described in CVE-2015-2189?
The vulnerability in CVE-2015-2189 is caused by an off-by-one error in the pcapng_read function, leading to out-of-bounds reads.
Can CVE-2015-2189 be exploited remotely?
Yes, CVE-2015-2189 can be exploited remotely by attackers using crafted files to trigger the vulnerability.