CVE-2016-4082: Buffer Overflow
epan/dissectors/packet-gsmcbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4082?
CVE-2016-4082 has been classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2016-4082?
To resolve CVE-2016-4082, upgrade to Wireshark version 1.12.11 or 2.0.3 or later.
Which versions of Wireshark are affected by CVE-2016-4082?
CVE-2016-4082 affects Wireshark versions 1.12.0 through 1.12.10 and 2.0.0 through 2.0.2.
What type of attack is associated with CVE-2016-4082?
CVE-2016-4082 allows remote attackers to leverage a crafted packet to trigger out-of-bounds access and cause an application crash.
Is there a workaround for CVE-2016-4082?
The only effective workaround for CVE-2016-4082 is to upgrade to a secured version of Wireshark as no configuration changes can mitigate the vulnerability.