CVE-2016-2522
published 2016-02-28CVE-2016-2522: The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that…
PriorityP424medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
2.08%
79.3th percentile
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 2.0.2+ga16e22e-1 (bookworm) | wireshark 2.0.2+ga16e22e-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: ASN.1 BER dissector crash (wnpa-sec-2016-02)
vendor_redhat·2016-02-26·CVSS 5.9
CVE-2016-2522 [MEDIUM] wireshark: ASN.1 BER dissector crash (wnpa-sec-2016-02)
wireshark: ASN.1 BER dissector crash (wnpa-sec-2016-02)
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Package: wireshark (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-2522: wireshark - The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c i...
vendor_debian·2016·CVSS 5.9
CVE-2016-2522 [MEDIUM] CVE-2016-2522: wireshark - The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c i...
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22e-1)
bullseye: resolved (fixed in 2.0.2+ga16e22e-1)
forky: resolved (fixed in 2.0.2+ga16e22e-1)
sid: resolved (fixed in 2.0.2+ga16e22e-1)
trixie: resolved (fixed in 2.0.2+ga16e22e-1)
GHSA
GHSA-2g5w-fjfx-gpv9: The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber
ghsa_unreviewed·2022-05-17
CVE-2016-2522 [MEDIUM] CWE-119 GHSA-2g5w-fjfx-gpv9: The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
OSV
CVE-2016-2522: The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber
osv·2016-02-28·CVSS 5.9
CVE-2016-2522 [MEDIUM] CVE-2016-2522: The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2522 wireshark: ASN.1 BER dissector crash (wnpa-sec-2016-02)
bugzilla·2016-02-29·CVSS 5.9
CVE-2016-2522 [MEDIUM] CVE-2016-2522 wireshark: ASN.1 BER dissector crash (wnpa-sec-2016-02)
CVE-2016-2522 wireshark: ASN.1 BER dissector crash (wnpa-sec-2016-02)
It was reported that Wireshark's ASN.1 BER dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11828
External References:
https://www.wireshark.org/security/wnpa-sec-2016-02.html
Bugzilla
CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion
bugzilla·2016-01-25·CVSS 6.5
CVE-2015-8781 [MEDIUM] CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion
CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion
A flaw was discovered in a way libtiff decodes special data. A potential out-of-bounds write could occur for specifically crafted images.
External bug report (CVE-2015-8781):
http://bugzilla.maptools.org/show_bug.cgi?id=2522
CVE assignments:
http://seclists.org/oss-sec/2016/q1/190
Upstream fix (for all CVEs):
https://github.com/vadz/libtiff/commit/aaab5c3c9d2a2c6984f23ccbc79702610439bc65
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1301650]
---
On RHEL5, 6, 7, and Fedora, libtiff is compiled with assertions enabled. Thus, the impact of these flaws is limited to triggering an assertion.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux
http://www.securitytracker.com/id/1035118http://www.wireshark.org/security/wnpa-sec-2016-02.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11828https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=9b2f3f7c5c9205381cb72e42b66e97d8ed3abf63https://security.gentoo.org/glsa/201604-05http://www.securitytracker.com/id/1035118http://www.wireshark.org/security/wnpa-sec-2016-02.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11828https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=9b2f3f7c5c9205381cb72e42b66e97d8ed3abf63https://security.gentoo.org/glsa/201604-05
2016-02-28
Published