CVE-2018-16057Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
0.6%
top 29.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.3-1 (bookworm)
Debianwireshark/wireshark< 2.6.3-1+3
NVDwireshark/wireshark2.2.02.2.16+2

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-984q-rhfc-9www: In Wireshark 22022-05-13
OSV
CVE-2018-16057: In Wireshark 22018-08-30

📋Vendor Advisories

2
Red Hat
wireshark: Radiotap dissector crash2018-08-29
Debian
CVE-2018-16057: wireshark - In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap d...2018

💬Community

2
Bugzilla
CVE-2018-16056 CVE-2018-16057 CVE-2018-16058 wireshark: various flaws [fedora-all]2018-09-06
Bugzilla
CVE-2018-16057 wireshark: Radiotap dissector crash2018-09-06