{ "schema_version": "1.4.0", "id": "GHSA-mh8p-r6wv-f24w", "modified": "2025-04-12T12:55:30Z", "published": "2022-05-17T03:24:42Z", "aliases": [ "CVE-2015-8734" ], "details": "The dissect_nwp function in epan/dissectors/packet-nwp.c in the NWP dissector in Wireshark 2.0.x before 2.0.1 mishandles the packet type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-8734" }, { "type": "WEB", "url": "https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11726" }, { "type": "WEB", "url": "https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=9b2c889abe0219fc162659e106c5b95deb6268f3" }, { "type": "WEB", "url": "https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=9b2c889abe0219fc162659e106c5b95deb6268f3" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201604-05" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1034551" }, { "type": "WEB", "url": "http://www.wireshark.org/security/wnpa-sec-2015-52.html" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2016-01-04T05:59:00Z" } }