epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0563
Reference (s):
- BID:71916
- URL: http://www.securityfocus.com/bid/71916
- http://advisories.mageia.org/MGASA-2015-0019.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html