PT-2016-7738 · Wireshark+2 · Wireshark+2
Published
2016-11-17
·
Updated
2024-06-15
·
CVE-2016-9374
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 2.0.0 through 2.0.7
Wireshark versions 2.2.0 through 2.2.1
Description
The issue is related to a buffer over-read in the AllJoyn dissector, which could cause a crash. This crash can be triggered by either network traffic or a capture file. The problem arises from a length variable not properly tracking the state of a signature variable.
Recommendations
For Wireshark versions 2.0.0 through 2.0.7, update to a version where the issue is fixed by ensuring the length variable properly tracks the state of the signature variable in the AllJoyn dissector.
For Wireshark versions 2.2.0 through 2.2.1, update to a version where the issue is fixed by ensuring the length variable properly tracks the state of the signature variable in the AllJoyn dissector.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Wireshark