CVE-2018-16058Improper Initialization in Wireshark

Severity
7.5HIGHNVD
EPSS
0.8%
top 26.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30
Latest updateMay 13

Description

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly initializing a data structure.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.6.3-1 (bookworm)
Debianwireshark/wireshark< 2.6.3-1+3
NVDwireshark/wireshark2.2.02.2.16+2

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-crq5-vjfj-jm52: In Wireshark 22022-05-13
OSV
CVE-2018-16058: In Wireshark 22018-08-30

📋Vendor Advisories

2
Red Hat
wireshark: Bluetooth AVDTP dissector crash2018-08-29
Debian
CVE-2018-16058: wireshark - In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth ...2018

💬Community

2
Bugzilla
CVE-2018-16058 wireshark: Bluetooth AVDTP dissector crash2018-09-06
Bugzilla
CVE-2018-16056 CVE-2018-16057 CVE-2018-16058 wireshark: various flaws [fedora-all]2018-09-06