CVE-2018-16056: High severity wireshark vulnerability
Published Aug 30, 2018
·Updated
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.
Affected Software
5 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.2.0<=2.2.16
Wireshark Wireshark>=2.4.0<=2.4.8
Wireshark Wireshark>=2.6.0<=2.6.2
Debian Debian Linux=9.0
Remediation
Event History
Aug 30, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16056?
CVE-2018-16056 has a medium severity level due to potential crashes in Wireshark when processing Bluetooth Attribute Protocol.
2
How do I fix CVE-2018-16056?
To fix CVE-2018-16056, upgrade Wireshark to version 2.6.20 or later, or 3.4.10 or later.
3
Which Wireshark versions are affected by CVE-2018-16056?
CVE-2018-16056 affects Wireshark versions 2.2.0 to 2.2.16, 2.4.0 to 2.4.8, and 2.6.0 to 2.6.2.
4
What types of protocols does CVE-2018-16056 impact?
CVE-2018-16056 specifically impacts the Bluetooth Attribute Protocol when dissected by Wireshark.
5
Is CVE-2018-16056 present in the latest version of Wireshark?
No, CVE-2018-16056 is not present in Wireshark versions released after the patches were applied.