5.9

CVE-2016-4085

Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Solaris Version 11.3
Debian ≫ Debian Linux Version 8.0
Wireshark ≫ Wireshark Version 1.12.0
Wireshark ≫ Wireshark Version 1.12.1
Wireshark ≫ Wireshark Version 1.12.2
Wireshark ≫ Wireshark Version 1.12.3
Wireshark ≫ Wireshark Version 1.12.4
Wireshark ≫ Wireshark Version 1.12.5
Wireshark ≫ Wireshark Version 1.12.6
Wireshark ≫ Wireshark Version 1.12.7
Wireshark ≫ Wireshark Version 1.12.8
Wireshark ≫ Wireshark Version 1.12.9
Wireshark ≫ Wireshark Version 1.12.10
Wireshark ≫ Wireshark Version 2.0.0
Wireshark ≫ Wireshark Version 2.0.1
Wireshark ≫ Wireshark Version 2.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.03% 0.858
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
Third Party Advisory
http://www.debian.org/security/2016/dsa-3585
Third Party Advisory
http://www.securitytracker.com/id/1035685
http://www.securityfocus.com/bid/87467
Third Party Advisory
VDB Entry
http://www.wireshark.org/security/wnpa-sec-2016-28.html
Vendor Advisory
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12293
Issue Tracking
https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=99efcb0f5aeeb4b2179e88c7a4233022aaeecf0b