CVE-2016-9375: Input Validation
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9375?
CVE-2016-9375 has a high severity rating due to its ability to cause an infinite loop, potentially leading to denial of service.
How do I fix CVE-2016-9375?
To fix CVE-2016-9375, upgrade to Wireshark version 2.2.2 or later, or version 2.0.8 or later.
Which versions of Wireshark are affected by CVE-2016-9375?
Versions of Wireshark from 2.0.0 to 2.0.7 and 2.2.0 to 2.2.1 are vulnerable to CVE-2016-9375.
What causes the vulnerability CVE-2016-9375?
CVE-2016-9375 is caused by the DTN dissector going into an infinite loop triggered by specific network traffic or capture files.
Has CVE-2016-9375 been addressed in software updates?
Yes, CVE-2016-9375 has been addressed in newer versions of Wireshark, specifically with checks added for successful SDNV evaluation.