SB2016091242 - Resource management error in wireshark (Alpine package)
Published: September 12, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2016-6506)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=012e5b8ddaa5ad3353e0df651fd6b2f2097705ab
- https://git.alpinelinux.org/aports/commit/?id=51b11a6ae20d7bcd9c086cafbe85688785b2d72e
- https://git.alpinelinux.org/aports/commit/?id=71e23d72a21db07cd80913b497c92f3b20585c2c
- https://git.alpinelinux.org/aports/commit/?id=f69acd7283a989adcfb4cccf1ce1648af851f990
- https://git.alpinelinux.org/aports/commit/?id=c50651068f78da271552efce20a0399ab88985f5
- https://git.alpinelinux.org/aports/commit/?id=e1d225fddc4d9dbb88b2f6f5bbcb4b00d04f5012