CVE-2016-6503: Input Validation
Published Aug 6, 2016
·Updated
The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected Software
5 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Remediation
Event History
Aug 6, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6503?
CVE-2016-6503 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-6503?
To mitigate CVE-2016-6503, upgrade Wireshark to version 2.0.5 or later.
3
What versions of Wireshark are affected by CVE-2016-6503?
Wireshark versions 2.0.0 through 2.0.4 are affected by CVE-2016-6503.
4
What type of attack does CVE-2016-6503 allow?
CVE-2016-6503 allows remote attackers to cause an application crash via crafted packets.
5
On which platform does CVE-2016-6503 impact Wireshark?
CVE-2016-6503 impacts Wireshark on 64-bit Windows platforms.