CVE-2018-16056Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
0.6%
top 31.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.3-1 (bookworm)
Debianwireshark/wireshark< 2.6.3-1+3
NVDwireshark/wireshark2.2.02.2.16+2

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-xfgw-27f6-g5xr: In Wireshark 22022-05-13
OSV
CVE-2018-16056: In Wireshark 22018-08-30

📋Vendor Advisories

2
Red Hat
wireshark: Bluetooth Attribute Protocol dissector crash2018-08-29
Debian
CVE-2018-16056: wireshark - In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth ...2018

💬Community

2
Bugzilla
CVE-2018-16056 wireshark: Bluetooth Attribute Protocol dissector crash2018-09-06
Bugzilla
CVE-2018-16056 CVE-2018-16057 CVE-2018-16058 wireshark: various flaws [fedora-all]2018-09-06