CVE-2016-4078
Last modified
CVE-2016-4078 is a vulnerability of currently unknown severity. The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted packet, related to epan/dissectors/packet-capwap.c and epan/dissectors/packet-ieee80211.c.. EPSS estimates a 2.12% chance of exploitation in the next 30 days.
Description
The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted packet, related to epan/dissectors/packet-capwap.c and epan/dissectors/packet-ieee80211.c.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wireshark | Wireshark | 1.12.0 |
| Wireshark | Wireshark | 1.12.1 |
| Wireshark | Wireshark | 1.12.2 |
| Wireshark | Wireshark | 1.12.3 |
| Wireshark | Wireshark | 1.12.4 |
| Wireshark | Wireshark | 1.12.5 |
| Wireshark | Wireshark | 1.12.6 |
| Wireshark | Wireshark | 1.12.7 |
| Wireshark | Wireshark | 1.12.8 |
| Wireshark | Wireshark | 1.12.9 |
| Wireshark | Wireshark | 1.12.10 |
| Wireshark | Wireshark | 2.0.0 |
| Wireshark | Wireshark | 2.0.1 |
| Wireshark | Wireshark | 2.0.2 |
References
- http://www.wireshark.org/security/wnpa-sec-2016-21.htmlVendor Advisory
- http://www.wireshark.org/security/wnpa-sec-2016-21.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-4078?
How severe is CVE-2016-4078?
How do I fix CVE-2016-4078?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-4072The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20…
- CVE-2016-4073Multiple integer overflows in the mbfl_strcut function in ex…
- CVE-2016-4074The jv_dump_term function in jq 1.5 allows remote attackers …7.5
- CVE-2016-4075Opera Mini 13 and Opera Stable 36 allow remote attackers to …6.1
- CVE-2016-4076epan/dissectors/packet-ncp2222.inc in the NCP dissector in W…
- CVE-2016-4077epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 …
- CVE-2016-4079epan/dissectors/packet-pktc.c in the PKTC dissector in Wires…
- CVE-2016-4080epan/dissectors/packet-pktc.c in the PKTC dissector in Wires…
- CVE-2016-4081epan/dissectors/packet-iax2.c in the IAX2 dissector in Wires…
- CVE-2016-4082epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector …
- CVE-2016-4083epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wi…
- CVE-2016-4084Integer signedness error in epan/dissectors/packet-mswsp.c i…
Are you affected by CVE-2016-4078?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
