CVE-2016-6512: Input Validation
Published Aug 6, 2016
·Updated
epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvbgetguintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors.
Affected Software
5 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Remediation
Event History
Aug 6, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6512?
CVE-2016-6512 has a high severity rating, as it allows remote attackers to cause a denial of service.
2
How do I fix CVE-2016-6512?
To fix CVE-2016-6512, update Wireshark to version 2.0.5 or later where the vulnerability has been addressed.
3
Which versions of Wireshark are affected by CVE-2016-6512?
CVE-2016-6512 affects Wireshark versions 2.0.0 through 2.0.4.
4
What type of attack does CVE-2016-6512 facilitate?
CVE-2016-6512 facilitates a denial of service attack that can lead to an infinite loop.
5
What component of Wireshark is impacted by CVE-2016-6512?
CVE-2016-6512 impacts the epan/dissectors component within Wireshark's handling of specific packet types.