CVE-2015-8728 – Wireshark - my_dgt_tbcd_unpack Static Buffer Overflow
https://notcve.org/view.php?id=CVE-2015-8728
The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly uses the tvb_bcd_dig_to_wmem_packet_str function, which allows remote attackers to cause a denial of service (buffer overflow and application crash) via a crafted packet. El analizador Mobile Identity en (1) epan/dissectors/packet-ansi_a.c en el disector ANSI A y (2) epan/dissectors/packet-gsm_a_common.c en el disector GSM A en Wireshark 1.12.x en versiones anteriores a 1.12.9 y 2.0.x en versiones anteriores a 2.0.1 utiliza indebidamente la función tvb_bcd_dig_to_wmem_packet_str, lo que permite a atacantes remotos provocar una denegación de servicio (desbordamiento de buffer y caída de aplicación) a través de un paquete manipulado. • https://www.exploit-db.com/exploits/39000 http://www.debian.org/security/2016/dsa-3505 http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html http://www.securityfocus.com/bid/79382 http://www.securitytracker.com/id/1034551 http://www.wireshark.org/security/wnpa-sec-2015-46.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11797 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=15edc8d714b11dcff3a04e5d00b8db9adfdb81ed https://security.gentoo.o • CWE-20: Improper Input Validation •
CVE-2015-8732 – Wireshark - dissect_zcl_pwr_prof_pwrprofstatersp Static Out-of-Bounds Read
https://notcve.org/view.php?id=CVE-2015-8732
The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the Total Profile Number field, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet. La función dissect_zcl_pwr_prof_pwrprofstatersp en epan/dissectors/packet-zbee-zcl-general.c en el disector ZigBee ZCL en Wireshark 1.12.x en versiones anteriores a 1.12.9 y 2.0.x en versiones anteriores a 2.0.1 no valida el campo Total Profile Number, lo que permite a atacantes remotos causar una denegación de servicio (lectura fuera de rango y caída de aplicación) a través de un paquete manipulado. • https://www.exploit-db.com/exploits/38995 http://www.debian.org/security/2016/dsa-3505 http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html http://www.securityfocus.com/bid/79382 http://www.securitytracker.com/id/1034551 http://www.wireshark.org/security/wnpa-sec-2015-50.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11830 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=9352616ec9742f2ed3d2802d0c8c100d51ca410b https://code.wireshark.or • CWE-20: Improper Input Validation •
CVE-2015-8727 – Wireshark - addresses_equal 'dissect_rsvp_common' Use-After-Free
https://notcve.org/view.php?id=CVE-2015-8727
The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not properly maintain request-key data, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet. La función dissect_rsvp_common en epan/dissectors/packet-rsvp.c en el disector RSVP en Wireshark 1.12.x en versiones anteriores a 1.12.9 y 2.0.x en versiones anteriores a 2.0.1 no mantiene adecuadmante los datos de petición de clave, lo que permite a atacantes remotos provocar una denegación de servicio (uso depués de liberación de memoria y caída de aplicación) a través de un paquete manipulado. • https://www.exploit-db.com/exploits/39002 http://www.debian.org/security/2016/dsa-3505 http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html http://www.securityfocus.com/bid/79382 http://www.securitytracker.com/id/1034551 http://www.wireshark.org/security/wnpa-sec-2015-45.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11793 https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=56baca60271379cb97f6a4a6bf72eb526e8b52d0 https://security.gentoo.o • CWE-20: Improper Input Validation •
CVE-2015-8711
https://notcve.org/view.php?id=CVE-2015-8711
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. epan/dissectors/packet-nbap.c en el disector NBAP en Wireshark 1.12.x en versiones anteriores a 1.12.9 y 2.0.x en versiones anteriores a 2.0.1 no valida datos de conversación, lo que permite a atacantes remotos provocar una denegación de servicio (referencia a puntero NULL y caída de aplicación) a través de un paquete manipulado. • http://www.debian.org/security/2016/dsa-3505 http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html http://www.securityfocus.com/bid/79814 http://www.securitytracker.com/id/1034551 http://www.wireshark.org/security/wnpa-sec-2015-31.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11602 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11835 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11841 https://code.wireshark.org/review/gitweb?p=wir • CWE-20: Improper Input Validation •
CVE-2015-8718
https://notcve.org/view.php?id=CVE-2015-8718
Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, when the "Match MSG/RES packets for async NLM" option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted packet. Vulnerabilidad de liberación doble en epan/dissectors/packet-nlm.c en el disector NLM en Wireshark 1.12.x en versiones anteriores a 1.12.9 y 2.0.x en versiones anterioers a 2.0.1, cuando la opción "Match MSG/RES packets for async NLM" está habilitada, permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un paquete manipulado. • http://www.debian.org/security/2016/dsa-3505 http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html http://www.securityfocus.com/bid/79814 http://www.securitytracker.com/id/1034551 http://www.wireshark.org/security/wnpa-sec-2015-37.html https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=81dfe6d450ada42d12f20ac26a6d8ae2302df37e https://security.gentoo.org/glsa/201604-05 • CWE-20: Improper Input Validation •