CVE-2015-2190
EPSS 0.30%
Description
epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet that is improperly handled by the LLDP dissector.
How to fix CVE-2015-2190
To remediate CVE-2015-2190, upgrade the affected package to a fixed version below.
- Debian/wireshark—upgrade to 1.12.1+g01b65bf-4 or later
Is CVE-2015-2190 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.12.1+g01b65bf-4