VulnerabilityModified
CVE-2016-9375
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file.
MEDIUM 5.9EPSS 1.59%
Does this matter?
Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.
Description
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-399
- Affected
- wireshark/wireshark · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2016/dsa-3719Third Party Advisory
- http://www.securityfocus.com/bid/94369Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037313
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13097Issue Tracking
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=be6a10afc59f8182b9884d02f9857d547539fe8a
- https://www.wireshark.org/security/wnpa-sec-2016-62.htmlVendor Advisory
- http://www.debian.org/security/2016/dsa-3719Third Party Advisory
- http://www.securityfocus.com/bid/94369Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037313
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13097Issue Tracking
- https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=be6a10afc59f8182b9884d02f9857d547539fe8a
- https://www.wireshark.org/security/wnpa-sec-2016-62.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.