SB2016091244 - Input validation error in wireshark (Alpine package)
Published: September 12, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2016-6509)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=012e5b8ddaa5ad3353e0df651fd6b2f2097705ab
- https://git.alpinelinux.org/aports/commit/?id=a3941a00036014165b8ba5ecdf3b74264d05f3c4
- https://git.alpinelinux.org/aports/commit/?id=9d9348a6385138edc94f93286dc49303108e973a
- https://git.alpinelinux.org/aports/commit/?id=fa1dda0548ea000a63dace45b2a940b9ed67e3b7
- https://git.alpinelinux.org/aports/commit/?id=6ebfa63cc3b58907d0d1ba7e084b3bd455bc6e93
- https://git.alpinelinux.org/aports/commit/?id=a1dc4c24d005744d531fa7f9250ed646b85975ff
- https://git.alpinelinux.org/aports/commit/?id=ba6830f4a71ca1ed8dc48aee9af0e7c91276ca04
- https://git.alpinelinux.org/aports/commit/?id=71e23d72a21db07cd80913b497c92f3b20585c2c
- https://git.alpinelinux.org/aports/commit/?id=f69acd7283a989adcfb4cccf1ce1648af851f990
- https://git.alpinelinux.org/aports/commit/?id=c50651068f78da271552efce20a0399ab88985f5
- https://git.alpinelinux.org/aports/commit/?id=e1d225fddc4d9dbb88b2f6f5bbcb4b00d04f5012