CVE-2016-9376: Medium severity wireshark vulnerability
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflowv5.c by ensuring that certain length values were sufficiently large.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9376?
CVE-2016-9376 is classified with a high severity due to its potential to cause application crashes through memory exhaustion.
How do I fix CVE-2016-9376?
To fix CVE-2016-9376, upgrade to Wireshark versions 2.0.8 or 2.2.2 or later.
What versions of Wireshark are affected by CVE-2016-9376?
CVE-2016-9376 affects Wireshark versions 2.0.0 to 2.0.7 and 2.2.0 to 2.2.1.
Can CVE-2016-9376 be exploited remotely?
Yes, CVE-2016-9376 can be exploited remotely via malicious network traffic or compromised capture files.
What type of vulnerability is CVE-2016-9376?
CVE-2016-9376 is a denial-of-service (DoS) vulnerability related to memory exhaustion in the OpenFlow dissector.