CVE-2016-5358

Source
https://cve.org/CVERecord?id=CVE-2016-5358
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5358.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-5358
Downstream
DEBIAN (1)
MGASA (1)
openSUSE (1)
SUSE (2)
UBUNTU (1)
Related
Published
2016-08-07T16:59:13Z
Modified
2026-07-08T12:05:58Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "11.3"
                },
                {
                    "last_affected":  "11.3"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:solaris"
        }
    ]
}
References

Affected packages

Git / github.com/wireshark/wireshark

Affected ranges

Type
GIT
Repo
https://github.com/wireshark/wireshark
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.3:*:*:*:*:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "2.0.0"
        },
        {
            "last_affected":  "2.0.0"
        },
        {
            "introduced":  "2.0.1"
        },
        {
            "last_affected":  "2.0.1"
        },
        {
            "introduced":  "2.0.2"
        },
        {
            "last_affected":  "2.0.2"
        },
        {
            "introduced":  "2.0.3"
        },
        {
            "last_affected":  "2.0.3"
        }
    ],
    "source":  [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
v2.*
v2.0.0
v2.0.1
v2.0.1rc0
v2.0.2
v2.0.2rc0
v2.0.3
v2.0.3rc0
v2.0.4rc0
wireshark-2.*
wireshark-2.0.0
wireshark-2.0.1
wireshark-2.0.2
wireshark-2.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5358.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "334449315304977340383420241633226719348",
                "320932733435266253742538915120566453735",
                "245578774751302863541828047293755008713",
                "30357838436267856021800050734870027683",
                "138813970532645865194505331319396360567",
                "307805584734905139821814819274303399748",
                "315719582076679645125194644249402846205",
                "209976510120667078380335317260493077732",
                "146747277072124464506533847220692900739"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2016-5358-01635744",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7",
        "target":  {
            "file":  "epan/dissectors/packet-ppi.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "299449988594139569541305770469884692042",
            "length":  6352
        },
        "id":  "CVE-2016-5358-21f495bd",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7",
        "target":  {
            "file":  "epan/dissectors/packet-ppi.c",
            "function":  "dissect_ppi"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "338752519889218304733566749802042023821",
            "length":  2107
        },
        "id":  "CVE-2016-5358-5ce2fd91",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7",
        "target":  {
            "file":  "epan/dissectors/packet-pktap.c",
            "function":  "dissect_pktap"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "330430542262926018448608795824361140614",
            "length":  1564
        },
        "id":  "CVE-2016-5358-637a8fc0",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7",
        "target":  {
            "file":  "epan/dissectors/packet-rpcap.c",
            "function":  "dissect_rpcap_packet"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "27916644768496533656810545275833789355",
                "37823342120425800220646364435165916704",
                "264994017350731906222936056776478734300",
                "132396777522632413076630297376118682332",
                "289632527312961041599743416980106338989",
                "134593429129036244985834589675552433877",
                "115801305615867899831225278823859525566",
                "209976510120667078380335317260493077732",
                "70616474456708318787207731558451418760"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2016-5358-649fa91b",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7",
        "target":  {
            "file":  "epan/dissectors/packet-pktap.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "216969062309645181064252099101574065597",
                "144417925569203975010017039560378111186",
                "279709717053073643829043742089946626936",
                "45601298362245210734312012769402793251",
                "170802040358257705377537301921365358538",
                "138838526760500685021898488601579542890",
                "109083495737063408071250071069583155465",
                "225064910552521824428069315849786949102"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2016-5358-d1613c7c",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7",
        "target":  {
            "file":  "epan/dissectors/packet-rpcap.c"
        }
    }
]
vanir_signatures_modified
"2026-07-08T12:05:58Z"

Git / gitlab.com/wireshark/wireshark

Affected ranges

Type
GIT
Repo
https://gitlab.com/wireshark/wireshark
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.2:*:*:*:*:*:*:*",
        "cpe:2.3:a:wireshark:wireshark:2.0.3:*:*:*:*:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "2.0.0"
        },
        {
            "last_affected":  "2.0.0"
        },
        {
            "introduced":  "2.0.1"
        },
        {
            "last_affected":  "2.0.1"
        },
        {
            "introduced":  "2.0.2"
        },
        {
            "last_affected":  "2.0.2"
        },
        {
            "introduced":  "2.0.3"
        },
        {
            "last_affected":  "2.0.3"
        }
    ],
    "source":  "CPE_STRING"
}

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
v2.*
v2.0.0
v2.0.1
v2.0.1rc0
v2.0.2
v2.0.2rc0
v2.0.3
v2.0.3rc0
wireshark-2.*
wireshark-2.0.0
wireshark-2.0.1
wireshark-2.0.2
wireshark-2.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5358.json"