The detect_version function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not check the length of the payload, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a packet with a crafted payload, as demonstrated by a length of zero, a different vulnerability than CVE-2015-3906.
2015-05-26T15:59:09.150
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | wireshark | wireshark | 1.12.0 | Yes |
| Application | wireshark | wireshark | 1.12.1 | Yes |
| Application | wireshark | wireshark | 1.12.2 | Yes |
| Application | wireshark | wireshark | 1.12.3 | Yes |
| Application | wireshark | wireshark | 1.12.4 | Yes |