SB2016091241 - Division by zero in wireshark (Alpine package)
Published: September 12, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Division by zero (CVE-ID: CVE-2016-6505)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to divide-by-zero error within epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5. A remote attacker can perform a denial of service (divide-by-zero error and application crash) via a crafted packet.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=012e5b8ddaa5ad3353e0df651fd6b2f2097705ab
- https://git.alpinelinux.org/aports/commit/?id=51b11a6ae20d7bcd9c086cafbe85688785b2d72e
- https://git.alpinelinux.org/aports/commit/?id=71e23d72a21db07cd80913b497c92f3b20585c2c
- https://git.alpinelinux.org/aports/commit/?id=f69acd7283a989adcfb4cccf1ce1648af851f990
- https://git.alpinelinux.org/aports/commit/?id=c50651068f78da271552efce20a0399ab88985f5
- https://git.alpinelinux.org/aports/commit/?id=e1d225fddc4d9dbb88b2f6f5bbcb4b00d04f5012