CVE-2016-2528: Input Validation
The dissectnhdrextopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2528?
CVE-2016-2528 has a high severity rating due to its potential to cause a denial of service through stack-based buffer overflow.
How do I fix CVE-2016-2528?
To fix CVE-2016-2528, upgrade Wireshark to version 2.0.2 or later, which addresses the vulnerability.
Who is affected by CVE-2016-2528?
CVE-2016-2528 affects users of Wireshark versions 2.0.0 and 2.0.1.
What type of attack does CVE-2016-2528 enable?
CVE-2016-2528 enables remote attackers to conduct denial of service attacks resulting in application crashes.
What component of Wireshark is vulnerable in CVE-2016-2528?
CVE-2016-2528 is related to the LBMC dissector in the Wireshark application.