CVE-2016-6512 describes a denial-of-service vulnerability in Wireshark versions 2.x prior to 2.0.5. The flaw, residing in the tvb_get_guintvar function within the epan/dissectors/packet-wap.c file, is due to a missing overflow check, allowing remote attackers to trigger an infinite loop via specially crafted packets processed by the MMSE, WAP, WBXML, and WSP dissectors. Rated Medium severity with a CVSS score of 5.9, this vulnerability has a high attack complexity but can lead to a complete denial of service. While there is no evidence of active exploitation, a public exploit (EDB-40195) exists, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:* | ||
2.0.2CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.2:*:*:*:*:*:*:* | ||
2.0.3CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.3:*:*:*:*:*:*:* | ||
2.0.4CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.