#VU14579 Improper input validation in Wireshark - CVE-2018-16056
Published: August 31, 2018
Wireshark
Wireshark.org
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to the epan/dissectors/packet-btatt.c source code file of the affected software does not verify that a dissector for a specific universally unique identifier (UUID) exists. A remote attacker can inject a malformed packet into a network, to be processed by the affected application, or trick the victim into opening a malicious packet trace file and cause the Bluetooth ATT dissector component to crash.