CVE-2016-7958: Input Validation
In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7958?
CVE-2016-7958 has been classified as a high severity vulnerability due to its potential to cause crashes in Wireshark.
How do I fix CVE-2016-7958?
To fix CVE-2016-7958, it is recommended to upgrade to a version of Wireshark later than 2.2.0 where this issue has been addressed.
Which versions of Wireshark are affected by CVE-2016-7958?
CVE-2016-7958 affects specifically Wireshark version 2.2.0.
What are the consequences of not addressing CVE-2016-7958?
Failing to address CVE-2016-7958 can lead to application crashes when using the NCP dissector, potentially resulting in loss of data or other disruptions.
Can packet injection triggers CVE-2016-7958?
Yes, packet injection or a malformed capture file can trigger CVE-2016-7958 and cause the application to crash.