CVE-2016-4077: Use After Free
Published Apr 25, 2016
·Updated
epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on incorrect special-case handling of truncated Tvb data structures, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.
Affected Software
3 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Event History
Apr 25, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4077?
CVE-2016-4077 has been classified as a denial-of-service vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2016-4077?
To mitigate CVE-2016-4077, upgrading TShark in Wireshark versions 2.0.3 or later is recommended.
3
Which versions of Wireshark are affected by CVE-2016-4077?
CVE-2016-4077 affects Wireshark versions 2.0.0, 2.0.1, and 2.0.2.
4
What type of attack does CVE-2016-4077 enable?
CVE-2016-4077 allows remote attackers to perform denial-of-service attacks via crafted packets.
5
What components of Wireshark are involved in CVE-2016-4077?
CVE-2016-4077 involves the epan/reassemble.c component in TShark.