Improper input validation in Wireshark - CVE-2018-16058
Published: August 31, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to the epan/dissectors/packet-btavdtp.c source code file of the affected software improperly initializes a data structure. A remote attacker can inject a malformed packet into a network, to be processed by the affected application, or trick the victim into opening a malicious packet trace file and cause the AVDTP dissector component to crash.
Affected software
Debian Linux
Opensuse
Fedora
wireshark (Alpine package)
wireshark
How to mitigate CVE-2018-16058
wireshark (Alpine package) - addressed in versions 2.4.9-r0, 2.6.3-r0
wireshark - addressed in versions 2.6.4-1.fc28, 2.6.4-1.fc29
External References
Related Security Bulletins
- Denial of service vulnerabilities in Wireshark
- OpenSUSE Linux update for wireshark
- OpenSUSE Linux update for wireshark
- Debian update for wireshark
- OpenSUSE Linux update for wireshark
- Improper input validation in wireshark (Alpine package)
- Fedora 29 update for wireshark
- Fedora 28 update for wireshark