Candidate: CVE-2015-3182 PublicDate: 2016-01-04 05:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3182 https://bugzilla.redhat.com/show_bug.cgi?id=1219409 Description: epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. Ubuntu-Description: Notes: sbeattie> wireshark 1.10 only according to RH bug Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_wireshark: upstream_wireshark: needs-triage precise_wireshark: ignored (reached end-of-life) precise/esm_wireshark: DNE (precise was needed) trusty_wireshark: released (2.6.3-1~ubuntu14.04.1) trusty/esm_wireshark: released (2.6.3-1~ubuntu14.04.1) utopic_wireshark: not-affected (1.10 only) vivid_wireshark: not-affected (1.10 only) vivid/stable-phone-overlay_wireshark: DNE vivid/ubuntu-core_wireshark: DNE wily_wireshark: not-affected (1.10 only) xenial_wireshark: released (2.6.3-1~ubuntu16.04.1) yakkety_wireshark: not-affected (1.10 only) zesty_wireshark: not-affected (1.10 only) artful_wireshark: not-affected (1.10 only) bionic_wireshark: released (2.6.3-1~ubuntu18.04.1) devel_wireshark: not-affected (2.6.3-1)