ZeroHour

CVE-2016-4079

CVSS 3.0
5.9 medium
EPSS
2%p81
Published
()
Modified
Description

epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.

Vendors
debianoraclewireshark
Products
debian linux, solaris, wireshark
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.