Wireshark TLS/SSL Decryption CVE-2015-0564 Denial of Service Vulnerability
BID:71922
Info
Wireshark TLS/SSL Decryption CVE-2015-0564 Denial of Service Vulnerability
| Bugtraq ID: | 71922 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2015-0564 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2015 12:00AM |
| Updated: | Feb 02 2016 08:08PM |
| Credit: | Noam Rathaus |
| Vulnerable: |
Wireshark Wireshark 1.12.2 Wireshark Wireshark 1.12.1 Wireshark Wireshark 1.12 Wireshark Wireshark 1.10.11 Wireshark Wireshark 1.10.10 Wireshark Wireshark 1.10.8 Wireshark Wireshark 1.10.7 Wireshark Wireshark 1.10.6 Wireshark Wireshark 1.10.5 Wireshark Wireshark 1.10.4 Wireshark Wireshark 1.10.3 Wireshark Wireshark 1.10.2 Wireshark Wireshark 1.10.1 Wireshark Wireshark 1.10 Wireshark Wireshark 1.10.9 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 7 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 7 Redhat Enterprise Linux Desktop 6 Oracle Linux 0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Wireshark Wireshark 1.12.3 Wireshark Wireshark 1.10.12 |
Discussion
Wireshark TLS/SSL Decryption CVE-2015-0564 Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark 1.12.0 through 1.12.2, and 1.10.0 through 1.10.11 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
An attacker can leverage this issue to crash the affected application, denying service to legitimate users.
Wireshark 1.12.0 through 1.12.2, and 1.10.0 through 1.10.11 are vulnerable.
Exploit / POC
Wireshark TLS/SSL Decryption CVE-2015-0564 Denial of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Wireshark TLS/SSL Decryption CVE-2015-0564 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva dumpcap-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark-devel-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wireshark3-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wiretap3-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64wsutil3-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rawshark-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tshark-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva wireshark-tools-1.10.12-1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Wireshark TLS/SSL Decryption CVE-2015-0564 Denial of Service Vulnerability
References:
References: