CVE-2016-4418: Buffer Overflow
epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4418?
CVE-2016-4418 has been classified as a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2016-4418?
To fix CVE-2016-4418, you should upgrade to Wireshark versions 1.12.10 or later, or 2.0.2 or later.
What type of vulnerability is CVE-2016-4418?
CVE-2016-4418 is a denial of service vulnerability that can lead to application crashes due to buffer over-reads.
Which versions of Wireshark are affected by CVE-2016-4418?
Affected versions of Wireshark include 1.12.0 to 1.12.9 and 2.0.0 to 2.0.1.
What can an attacker do with CVE-2016-4418?
An attacker can exploit CVE-2016-4418 by sending crafted packets that trigger an empty set, leading to application crashes.