CVE-2015-6241

Published: 24 August 2015

The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Priority

Medium

Status

Package Release Status
wireshark
Launchpad, Ubuntu, Debian
Upstream
Released (1.2.7)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (2.6.3-1~ubuntu18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (2.6.3-1~ubuntu16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.6.3-1~ubuntu14.04.1)
Patches:
Upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=6126a6455058696dd0ac2073032bdfe066a6ae38