peter bassill · operator
$ cve CVE-2015-8723 JSON

CVE-2015-8723 EXPLOIT

5.5
MEDIUM · CVSS 3.0 · EPSS 4.7% (pctl 92)

Patch early

A public exploit exists.

Description

The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

Scoring

CVSS5.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS4.69% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2016-01-04
Last modified2026-06-17

Affected (1)

VendorProduct
wiresharkwireshark

Public exploits

SourceTitleDate
exploit-dbWireshark - AirPDcapPacketProcess Stack Buffer Overflow2015-12-16

References

→ the Explorer  ·  watch your stack  ·  NVD