Improper input validation in Wireshark - CVE-2018-16056
Published: August 31, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to the epan/dissectors/packet-btatt.c source code file of the affected software does not verify that a dissector for a specific universally unique identifier (UUID) exists. A remote attacker can inject a malformed packet into a network, to be processed by the affected application, or trick the victim into opening a malicious packet trace file and cause the Bluetooth ATT dissector component to crash.
Affected software
Debian Linux
Opensuse
openEuler
Fedora
wireshark (Alpine package)
wireshark
wireshark-debuginfo
wireshark-debugsource
wireshark-devel
wireshark-help
How to mitigate CVE-2018-16056
wireshark (Alpine package) - addressed in versions 2.4.9-r0, 2.6.3-r0
wireshark - update to 2.6.2-11
wireshark-debuginfo - update to 2.6.2-11
wireshark-debugsource - update to 2.6.2-11
wireshark-devel - update to 2.6.2-11
wireshark-help - update to 2.6.2-11
wireshark - addressed in versions 2.6.4-1.fc28, 2.6.4-1.fc29
External References
Related Security Bulletins
- Denial of service vulnerabilities in Wireshark
- OpenSUSE Linux update for wireshark
- OpenSUSE Linux update for wireshark
- Debian update for wireshark
- OpenSUSE Linux update for wireshark
- Improper input validation in wireshark (Alpine package)
- openEuler 20.03 LTS update for wireshark
- Fedora 29 update for wireshark
- Fedora 28 update for wireshark