CVE Vulnerabilities

CVE-2016-6504

NULL Pointer Dereference

Published: Aug 06, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark1.12.0 (including)1.12.0 (including)
WiresharkWireshark1.12.1 (including)1.12.1 (including)
WiresharkWireshark1.12.2 (including)1.12.2 (including)
WiresharkWireshark1.12.3 (including)1.12.3 (including)
WiresharkWireshark1.12.4 (including)1.12.4 (including)
WiresharkWireshark1.12.5 (including)1.12.5 (including)
WiresharkWireshark1.12.6 (including)1.12.6 (including)
WiresharkWireshark1.12.7 (including)1.12.7 (including)
WiresharkWireshark1.12.8 (including)1.12.8 (including)
WiresharkWireshark1.12.9 (including)1.12.9 (including)
WiresharkWireshark1.12.10 (including)1.12.10 (including)
WiresharkWireshark1.12.11 (including)1.12.11 (including)
WiresharkWireshark1.12.12 (including)1.12.12 (including)
WiresharkUbuntuesm-infra-legacy/trusty*
WiresharkUbuntuprecise*
WiresharkUbuntutrusty*
WiresharkUbuntutrusty/esm*
WiresharkUbuntuupstream*

Potential Mitigations

References