CVE-2018-16057: High severity wireshark vulnerability
Published Aug 30, 2018
·Updated
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations.
Affected Software
6 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.2.0<=2.2.16
Wireshark Wireshark>=2.4.0<=2.4.8
Wireshark Wireshark>=2.6.0<=2.6.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Aug 30, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16057?
CVE-2018-16057 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-16057?
To fix CVE-2018-16057, update Wireshark to version 2.6.20 or later.
3
Which versions of Wireshark are affected by CVE-2018-16057?
CVE-2018-16057 affects Wireshark versions 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16.
4
What type of vulnerability is CVE-2018-16057?
CVE-2018-16057 is a denial-of-service vulnerability caused by a crash in the Radiotap dissector.
5
Is CVE-2018-16057 present in Debian distributions?
Yes, CVE-2018-16057 is present in certain Debian distributions running affected versions of Wireshark.