CVE-2015-8716
Published: 04 January 2016
The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conversation exists, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Priority
CVSS 3 base score: 5.5
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8716
- https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=eb6ccb1b0c4ad02b828652c3fe6e8d51c30a315e
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9887
- http://www.wireshark.org/security/wnpa-sec-2015-35.html
- NVD
- Launchpad
- Debian