The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (invalid write operation and application crash) via a crafted packet.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | Aug 30, 2017 | Jan 4, 2016 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Jan 4, 2016 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Jan 4, 2016 |
| Suse | — | Upgrade wireshark-ui-qtUpgrade libwsutil8Upgrade libwireshark9Upgrade wiresharkUpgrade libwscodecs1Upgrade libwiretap10Upgrade wireshark-develUpgrade libwsutil11Upgrade libwiretap7Upgrade libwireshark13 | Dec 9, 2016 | Jan 4, 2016 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Jan 4, 2016 |
| Wireshark | — | Upgrade to Wireshark version 2.0.1 | Oct 4, 2017 | Jan 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub