CVE-2016-2528
published 2016-02-28CVE-2016-2528: The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
2.21%
80.5th percentile
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 2.0.2+ga16e22e-1 (bookworm) | wireshark 2.0.2+ga16e22e-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
| wireshark | wireshark | >= 0 < 2.0.2+ga16e22e-1 | 2.0.2+ga16e22e-1 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: LBMC dissector crash (wnpa-sec-2016-08)
vendor_redhat·2016-02-26·CVSS 5.9
CVE-2016-2528 [MEDIUM] wireshark: LBMC dissector crash (wnpa-sec-2016-08)
wireshark: LBMC dissector crash (wnpa-sec-2016-08)
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Package: wireshark (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-2528: wireshark - The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC di...
vendor_debian·2016·CVSS 5.9
CVE-2016-2528 [MEDIUM] CVE-2016-2528: wireshark - The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC di...
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
Scope: local
bookworm: resolved (fixed in 2.0.2+ga16e22e-1)
bullseye: resolved (fixed in 2.0.2+ga16e22e-1)
forky: resolved (fixed in 2.0.2+ga16e22e-1)
sid: resolved (fixed in 2.0.2+ga16e22e-1)
trixie: resolved (fixed in 2.0.2+ga16e22e-1)
GHSA
GHSA-4c7r-2m52-xmv2: The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc
ghsa_unreviewed·2022-05-17
CVE-2016-2528 [MEDIUM] CWE-20 GHSA-4c7r-2m52-xmv2: The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
OSV
CVE-2016-2528: The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc
osv·2016-02-28·CVSS 5.9
CVE-2016-2528 [MEDIUM] CVE-2016-2528: The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3108 pulp: Insecure temporary file used when generating certificate for Pulp Nodes
bugzilla·2016-04-11·CVSS 7.1
CVE-2016-3108 [HIGH] CVE-2016-3108 pulp: Insecure temporary file used when generating certificate for Pulp Nodes
CVE-2016-3108 pulp: Insecure temporary file used when generating certificate for Pulp Nodes
It was reported that pulp-gen-nodes-certificate script uses insecurely created temporary files for storing the generated node certificates, allowing local attackers to leak the keys or overwrite arbitrary file via symlink.
Discussion:
Acknowledgments:
Name: Jeremy Cline (Red Hat), Sander Bos
---
Created attachment 1145990
Proposed patch
---
Created attachment 1146475
Proposed patch
I am attaching a revised version of the patch that removes the unneeded umask statement, and credits jcline in the commit message.
---
This is reported upstream as #1830 and is fixed by PR #2528:
https://pulp.plan.io/issues/1830
https://github.com/pulp/pulp/pull/2528
---
The Pulp upstream bug status is at CL
Bugzilla
CVE-2016-2528 wireshark: LBMC dissector crash (wnpa-sec-2016-08)
bugzilla·2016-02-29·CVSS 5.9
CVE-2016-2528 [MEDIUM] CVE-2016-2528 wireshark: LBMC dissector crash (wnpa-sec-2016-08)
CVE-2016-2528 wireshark: LBMC dissector crash (wnpa-sec-2016-08)
It was reported that Wireshark's LBMC dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11984
External References:
https://www.wireshark.org/security/wnpa-sec-2016-08.html
http://www.securitytracker.com/id/1035118http://www.wireshark.org/security/wnpa-sec-2016-08.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11984https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=1c090e929269a78bf7a4cb3dc0d34565f4351312https://security.gentoo.org/glsa/201604-05http://www.securitytracker.com/id/1035118http://www.wireshark.org/security/wnpa-sec-2016-08.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11984https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=1c090e929269a78bf7a4cb3dc0d34565f4351312https://security.gentoo.org/glsa/201604-05
2016-02-28
Published