CVE-2016-5359: Buffer Overflow
Published Aug 7, 2016
·Updated
epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet.
Affected Software
12 affected components
Wireshark Wireshark=1.12.0
Wireshark Wireshark=1.12.1
Wireshark Wireshark=1.12.2
Wireshark Wireshark=1.12.3
Wireshark Wireshark=1.12.4
Wireshark Wireshark=1.12.5
Wireshark Wireshark=1.12.6
Wireshark Wireshark=1.12.7
Wireshark Wireshark=1.12.8
Wireshark Wireshark=1.12.9
Wireshark Wireshark=1.12.10
Wireshark Wireshark=1.12.11
Event History
Aug 7, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5359?
CVE-2016-5359 has a severity rating of medium as it allows for remote denial of service attacks.
2
How do I fix CVE-2016-5359?
To fix CVE-2016-5359, upgrade to Wireshark version 1.12.12 or later.
3
What systems are affected by CVE-2016-5359?
CVE-2016-5359 affects Wireshark versions 1.12.0 through 1.12.11.
4
What kind of attack does CVE-2016-5359 allow?
CVE-2016-5359 allows remote attackers to cause a denial of service through crafted packets.
5
Is CVE-2016-5359 a user-exploitable vulnerability?
Yes, CVE-2016-5359 can be exploited by users sending specially crafted packets to the affected Wireshark versions.