CVE-2016-7957: Input Validation
Published Apr 12, 2017
·Updated
In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.
Affected Software
1 affected component
Wireshark Wireshark=2.2.0
Remediation
Patch Available
Event History
Apr 12, 2017
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7957?
CVE-2016-7957 has been classified as a high severity vulnerability due to the potential for application crashes.
2
How do I fix CVE-2016-7957?
To fix CVE-2016-7957, upgrade Wireshark to version 2.2.1 or later, where this vulnerability has been addressed.
3
What versions of Wireshark are affected by CVE-2016-7957?
CVE-2016-7957 specifically affects Wireshark version 2.2.0.
4
What attack vectors can trigger CVE-2016-7957?
CVE-2016-7957 can be triggered by packet injection or a malformed capture file.
5
What component of Wireshark does CVE-2016-7957 involve?
CVE-2016-7957 involves the Bluetooth L2CAP dissector within Wireshark.