The logcat_dump_text function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not properly handle a lack of \0 termination, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted message in a packet, a different vulnerability than CVE-2015-3815.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | May 26, 2015 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | May 26, 2015 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | May 26, 2015 |
| Wireshark | — | Upgrade to Wireshark version 1.12.5 | Apr 25, 2018 | May 26, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub