CVE-2016-2523
Publication date 28 February 2016
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| wireshark | 18.04 LTS bionic | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      
| 16.04 LTS xenial | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 14.04 LTS trusty | 
                              
                               
                                Fixed 1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1 
                                
                               
                             |      
                          
                            
                          
                        
                      |
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 
                      
                      
                         | 
                  
| Attack vector | Network | 
| Attack complexity | High | 
| Privileges required | None | 
| User interaction | None | 
| Scope | Unchanged | 
| Confidentiality | None | 
| Integrity impact | None | 
| Availability impact | High | 
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H | 
References
Other references
- https://www.wireshark.org/security/wnpa-sec-2016-03.html
 - https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=260afe11feb796d1fde992d8f8c133ebd950b573
 - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11938
 - http://www.wireshark.org/security/wnpa-sec-2016-03.html
 - https://www.cve.org/CVERecord?id=CVE-2016-2523