Vulnerabilities > CVE-2015-3811 - Code vulnerability in multiple products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Gentoo Local Security Checks NASL id GENTOO_GLSA-201510-03.NASL description The remote host is affected by the vulnerability described in GLSA-201510-03 (Wireshark: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in Wireshark. Please review the CVE identifiers referenced below for details. Impact : A remote attacker could possibly cause a Denial of Service condition. Workaround : There is no known workaround at this time. last seen 2020-06-01 modified 2020-06-02 plugin id 86688 published 2015-11-02 reporter This script is Copyright (C) 2015-2016 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/86688 title GLSA-201510-03 : Wireshark: Multiple vulnerabilities NASL family CentOS Local Security Checks NASL id CENTOS_RHSA-2015-2393.NASL description Updated wireshark packages that fix multiple security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-2188, CVE-2015-2189, CVE-2015-2191, CVE-2015-3810, CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2014-8710, CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714, CVE-2015-0562, CVE-2015-0563, CVE-2015-0564, CVE-2015-3182, CVE-2015-6243, CVE-2015-6244, CVE-2015-6245, CVE-2015-6246, CVE-2015-6248) The CVE-2015-3182 issue was discovered by Martin Zember of Red Hat. The wireshark packages have been upgraded to upstream version 1.10.14, which provides a number of bug fixes and enhancements over the previous version. (BZ#1238676) This update also fixes the following bug : * Prior to this update, when using the tshark utility to capture packets over the interface, tshark failed to create output files in the .pcap format even if it was specified using the last seen 2020-06-01 modified 2020-06-02 plugin id 87156 published 2015-12-02 reporter This script is Copyright (C) 2015-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/87156 title CentOS 7 : wireshark (CESA-2015:2393) NASL family Debian Local Security Checks NASL id DEBIAN_DLA-241.NASL description The following vulnerabilities were discovered in the Squeeze LTS last seen 2020-03-17 modified 2015-06-11 plugin id 84093 published 2015-06-11 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/84093 title Debian DLA-241-1 : wireshark security update NASL family Red Hat Local Security Checks NASL id REDHAT-RHSA-2017-0631.NASL description An update for wireshark is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Security Fix(es) : * Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2013-4075) Additional Changes : For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section. last seen 2020-06-01 modified 2020-06-02 plugin id 97877 published 2017-03-22 reporter This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/97877 title RHEL 6 : wireshark (RHSA-2017:0631) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-3277.NASL description Multiple vulnerabilities were discovered in the dissectors/parsers for LBMR, web sockets, WCP, X11, IEEE 802.11 and Android Logcat, which could result in denial of service. last seen 2020-06-01 modified 2020-06-02 plugin id 83960 published 2015-06-03 reporter This script is Copyright (C) 2015-2018 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/83960 title Debian DSA-3277-1 : wireshark - security update NASL family Windows NASL id WIRESHARK_1_12_5.NASL description The version of Wireshark installed on the remote Windows host is 1.10.x prior to 1.10.14, or 1.12.x prior to 1.12.5. It is, therefore, affected by various denial of service vulnerabilities in the following items : - LBMR dissector (CVE-2015-3808, CVE-2015-3809) - WebSocket dissector (CVE-2015-3810) - WCP dissector (CVE-2015-3811) - X11 dissector (CVE-2015-3812) - Packet reassembly code (CVE-2015-3813) - IEEE 802.11 dissector (CVE-2015-3814) - Android Logcat file parser (CVE-2015-3815, CVE-2015-3906) A remote attacker can exploit these vulnerabilities to cause Wireshark to crash or consume excessive CPU resources, either by injecting a specially crafted packet onto the wire or by convincing a user to read a malformed packet trace or PCAP file. Note that Nessus has not tested for these issues but has instead relied only on the application last seen 2020-06-01 modified 2020-06-02 plugin id 83488 published 2015-05-15 reporter This script is Copyright (C) 2015-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/83488 title Wireshark 1.10.x < 1.10.14 / 1.12.x < 1.12.5 Multiple DoS Vulnerabilities NASL family Red Hat Local Security Checks NASL id REDHAT-RHSA-2015-2393.NASL description Updated wireshark packages that fix multiple security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-2188, CVE-2015-2189, CVE-2015-2191, CVE-2015-3810, CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2014-8710, CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714, CVE-2015-0562, CVE-2015-0563, CVE-2015-0564, CVE-2015-3182, CVE-2015-6243, CVE-2015-6244, CVE-2015-6245, CVE-2015-6246, CVE-2015-6248) The CVE-2015-3182 issue was discovered by Martin Zember of Red Hat. The wireshark packages have been upgraded to upstream version 1.10.14, which provides a number of bug fixes and enhancements over the previous version. (BZ#1238676) This update also fixes the following bug : * Prior to this update, when using the tshark utility to capture packets over the interface, tshark failed to create output files in the .pcap format even if it was specified using the last seen 2020-06-01 modified 2020-06-02 plugin id 86988 published 2015-11-20 reporter This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/86988 title RHEL 7 : wireshark (RHSA-2015:2393) NASL family SuSE Local Security Checks NASL id SUSE_SU-2015-1098-1.NASL description Wireshark was updated and fixes the following issues : CVE-2015-3811: The WCP dissector could crash while decompressing data. CVE-2015-3812: The X11 dissector could leak memory CVE-2015-3814: The IEEE 802.11 dissector could go into an infinite loop. Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 84361 published 2015-06-24 reporter This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/84361 title SUSE SLED11 / SLES11 Security Update : wireshark (SUSE-SU-2015:1098-1) NASL family Scientific Linux Local Security Checks NASL id SL_20151119_WIRESHARK_ON_SL7_X.NASL description Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-2188, CVE-2015-2189, CVE-2015-2191, CVE-2015-3810, CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2014-8710, CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714, CVE-2015-0562, CVE-2015-0563, CVE-2015-0564, CVE-2015-3182, CVE-2015-6243, CVE-2015-6244, CVE-2015-6245, CVE-2015-6246, CVE-2015-6248) The wireshark packages have been upgraded to upstream version 1.10.14, which provides a number of bug fixes and enhancements over the previous version. This update also fixes the following bug : - Prior to this update, when using the tshark utility to capture packets over the interface, tshark failed to create output files in the .pcap format even if it was specified using the last seen 2020-03-18 modified 2015-12-22 plugin id 87578 published 2015-12-22 reporter This script is Copyright (C) 2015-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/87578 title Scientific Linux Security Update : wireshark on SL7.x x86_64 (20151119) NASL family SuSE Local Security Checks NASL id SUSE_SU-2015-1046-1.NASL description Wireshark was updated to 1.10.14 to fix four security issues. The following vulnerabilities have been fixed : - CVE-2015-3811: The WCP dissector could crash while decompressing data. (wnpa-sec-2015-14) - CVE-2015-3812: The X11 dissector could leak memory. (wnpa-sec-2015-15) - CVE-2015-3813: The packet reassembly code could leak memory. (wnpa-sec-2015-16) - CVE-2015-3814: The IEEE 802.11 dissector could go into an infinite loop. (wnpa-sec-2015-17) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 84191 published 2015-06-15 reporter This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/84191 title SUSE SLED12 / SLES12 Security Update : wireshark (SUSE-SU-2015:1046-1) NASL family CentOS Local Security Checks NASL id CENTOS_RHSA-2017-0631.NASL description An update for wireshark is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Security Fix(es) : * Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2013-4075) Additional Changes : For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section. last seen 2020-06-01 modified 2020-06-02 plugin id 97954 published 2017-03-27 reporter This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/97954 title CentOS 6 : wireshark (CESA-2017:0631) NASL family Oracle Linux Local Security Checks NASL id ORACLELINUX_ELSA-2015-2393.NASL description From Red Hat Security Advisory 2015:2393 : Updated wireshark packages that fix multiple security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-2188, CVE-2015-2189, CVE-2015-2191, CVE-2015-3810, CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2014-8710, CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714, CVE-2015-0562, CVE-2015-0563, CVE-2015-0564, CVE-2015-3182, CVE-2015-6243, CVE-2015-6244, CVE-2015-6245, CVE-2015-6246, CVE-2015-6248) The CVE-2015-3182 issue was discovered by Martin Zember of Red Hat. The wireshark packages have been upgraded to upstream version 1.10.14, which provides a number of bug fixes and enhancements over the previous version. (BZ#1238676) This update also fixes the following bug : * Prior to this update, when using the tshark utility to capture packets over the interface, tshark failed to create output files in the .pcap format even if it was specified using the last seen 2020-06-01 modified 2020-06-02 plugin id 87038 published 2015-11-24 reporter This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/87038 title Oracle Linux 7 : wireshark (ELSA-2015-2393) NASL family SuSE Local Security Checks NASL id OPENSUSE-2015-380.NASL description Wireshark was updated to 1.10.14 to fix three security issues and bugs. The following vulnerabilities were fixed : - CVE-2015-3811: The WCP dissector could crash while decompressing data (wnpa-sec-2015-14) - CVE-2015-3812: The X11 dissector could leak memory (wnpa-sec-2015-15) - CVE-2015-3814: The IEEE 802.11 dissector could go into an infinite loop (wnpa-sec-2015-17) last seen 2020-06-05 modified 2015-05-26 plugin id 83806 published 2015-05-26 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/83806 title openSUSE Security Update : Wireshark (openSUSE-2015-380) NASL family Scientific Linux Local Security Checks NASL id SL_20170321_WIRESHARK_ON_SL6_X.NASL description Security Fix(es) : - Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2013-4075) last seen 2020-03-18 modified 2017-04-06 plugin id 99228 published 2017-04-06 reporter This script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/99228 title Scientific Linux Security Update : wireshark on SL6.x i386/x86_64 (20170321) NASL family Oracle Linux Local Security Checks NASL id ORACLELINUX_ELSA-2017-0631.NASL description From Red Hat Security Advisory 2017:0631 : An update for wireshark is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Security Fix(es) : * Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2015-3811, CVE-2015-3812, CVE-2015-3813, CVE-2013-4075) Additional Changes : For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.9 Release Notes and Red Hat Enterprise Linux 6.9 Technical Notes linked from the References section. last seen 2020-06-01 modified 2020-06-02 plugin id 99066 published 2017-03-30 reporter This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/99066 title Oracle Linux 6 : wireshark (ELSA-2017-0631) NASL family Amazon Linux Local Security Checks NASL id ALA_ALAS-2017-813.NASL description Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. last seen 2020-06-01 modified 2020-06-02 plugin id 99186 published 2017-04-05 reporter This script is Copyright (C) 2017-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/99186 title Amazon Linux AMI : wireshark (ALAS-2017-813) NASL family SuSE Local Security Checks NASL id OPENSUSE-2015-379.NASL description Wireshark was updated to 1.12.5 to fix security issues and bugs. The following vulnerabilities have been fixed : - CVE-2015-3808, CVE-2015-3809: The LBMR dissector could go into an infinite loop. (wnpa-sec-2015-12) - CVE-2015-3810: The WebSocket dissector could recurse excessively. (wnpa-sec-2015-13) - CVE-2015-3811: The WCP dissector could crash while decompressing data. (wnpa-sec-2015-14) - CVE-2015-3812: The X11 dissector could leak memory. (wnpa-sec-2015-15) - CVE-2015-3813: The packet reassembly code could leak memory. (wnpa-sec-2015-16) - CVE-2015-3814: The IEEE 802.11 dissector could go into an infinite loop. (wnpa-sec-2015-17) - CVE-2015-3815: The Android Logcat file parser could crash. (wnpa-sec-2015-18) last seen 2020-06-05 modified 2015-05-26 plugin id 83805 published 2015-05-26 reporter This script is Copyright (C) 2015-2020 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/83805 title openSUSE Security Update : Wireshark (openSUSE-2015-379) NASL family NewStart CGSL Local Security Checks NASL id NEWSTART_CGSL_NS-SA-2019-0103_WIRESHARK.NASL description The remote NewStart CGSL host, running version MAIN 4.05, has wireshark packages installed that are affected by multiple vulnerabilities: - A flaw was found in X11 dissector of wireshark of which an attacker could make wireshark consume excessive CPU resources which could make system unresponsive by injecting specially crafted packet onto the wire or by convincing wireshark user to read malformed packet trace file. (CVE-2015-3812) - A flaw was found in WCP dissector of wireshark of which an attacker could crash wireshark by injecting a specially crafted packet onto the wire or by convincing wireshark user to read malformed packet trace file. (CVE-2015-3811) - A flaw was found in the way packet reassembly code of wireshark would parse a packet which could leak memory. An attacker could use this flaw to crash wireshark by sending a specially crafted packet onto the wire or by convincing wireshark user to read malformed packet trace file. (CVE-2015-3813) - A flaw was found in GMR (Geo-Mobile Radio) 1 BCCH protocol dissector of wireshark which an attacker can trigger a denial of service attack and crash wireshark by sending a specially crafted packet onto the wire or by convincing wireshark user to read malformed packet trace file. (CVE-2013-4075) Note that Nessus has not tested for this issue but has instead relied only on the application last seen 2020-06-01 modified 2020-06-02 plugin id 127333 published 2019-08-12 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/127333 title NewStart CGSL MAIN 4.05 : wireshark Multiple Vulnerabilities (NS-SA-2019-0103) NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_A13500D0057011E5AAB1D050996490D0.NASL description Wireshark development team reports : The following vulnerabilities have been fixed. - wnpa-sec-2015-12 The LBMR dissector could go into an infinite loop. (Bug 11036) CVE-2015-3808, CVE-2015-3809 - wnpa-sec-2015-13 The WebSocket dissector could recurse excessively. (Bug 10989) CVE-2015-3810 - wnpa-sec-2015-14 The WCP dissector could crash while decompressing data. (Bug 10978) CVE-2015-3811 - wnpa-sec-2015-15 The X11 dissector could leak memory. (Bug 11088) CVE-2015-3812 - wnpa-sec-2015-16 The packet reassembly code could leak memory. (Bug 11129) CVE-2015-3813 - wnpa-sec-2015-17 The IEEE 802.11 dissector could go into an infinite loop. (Bug 11110) CVE-2015-3814 - wnpa-sec-2015-18 The Android Logcat file parser could crash. Discovered by Hanno Bock. (Bug 11188) CVE-2015-3815 last seen 2020-06-01 modified 2020-06-02 plugin id 83902 published 2015-05-29 reporter This script is Copyright (C) 2015-2018 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/83902 title FreeBSD : wireshark -- multiple vulnerabilities (a13500d0-0570-11e5-aab1-d050996490d0)
Redhat
advisories |
| ||||
rpms |
|
References
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10978
- http://www.wireshark.org/security/wnpa-sec-2015-14.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.debian.org/security/2015/dsa-3277
- https://security.gentoo.org/glsa/201510-03
- http://rhn.redhat.com/errata/RHSA-2017-0631.html
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=a6fc6aa0b4efc1a1c3d7a2e3b5189e888fb6ccc2