{"id":"CVE-2016-5355","details":"wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.","modified":"2026-07-08T12:52:51.068745Z","published":"2016-08-07T16:59:09.503Z","related":["SUSE-SU-2016:2212-1","SUSE-SU-2016:2453-1","openSUSE-SU-2024:10199-1"],"references":[{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/91140"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3615"},{"type":"ADVISORY","url":"https://www.wireshark.org/security/wnpa-sec-2016-34.html"},{"type":"REPORT","url":"https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12394"},{"type":"FIX","url":"https://github.com/wireshark/wireshark/commit/3270dfac43da861c714df76513456b46765ff47f"},{"type":"FIX","url":"https://github.com/wireshark/wireshark/commit/5efb45231671baa2db2011d8f67f9d6e72bc455b"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/06/09/3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wireshark/wireshark","events":[{"introduced":"4fab41a1f0e14e9124ea6a61e7bae42e95599495"},{"last_affected":"eed34f0ac6696c053585ddf75c5805b3d5b395cf"},{"fixed":"3270dfac43da861c714df76513456b46765ff47f"},{"fixed":"5efb45231671baa2db2011d8f67f9d6e72bc455b"}],"database_specific":{"cpe":["cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.5:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.6:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.7:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.8:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.9:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.10:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.11:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.2:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.12.0"},{"last_affected":"1.12.0"},{"introduced":"1.12.1"},{"last_affected":"1.12.1"},{"introduced":"1.12.2"},{"last_affected":"1.12.2"},{"introduced":"1.12.3"},{"last_affected":"1.12.3"},{"introduced":"1.12.4"},{"last_affected":"1.12.4"},{"introduced":"1.12.5"},{"last_affected":"1.12.5"},{"introduced":"1.12.6"},{"last_affected":"1.12.6"},{"introduced":"1.12.7"},{"last_affected":"1.12.7"},{"introduced":"1.12.8"},{"last_affected":"1.12.8"},{"introduced":"1.12.9"},{"last_affected":"1.12.9"},{"introduced":"1.12.10"},{"last_affected":"1.12.10"},{"introduced":"1.12.11"},{"last_affected":"1.12.11"},{"introduced":"2.0.0"},{"last_affected":"2.0.0"},{"introduced":"2.0.1"},{"last_affected":"2.0.1"},{"introduced":"2.0.2"},{"last_affected":"2.0.2"},{"introduced":"2.0.3"},{"last_affected":"2.0.3"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.12.0","1.12.1","1.12.10","1.12.11","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12.7","1.12.8","1.12.9","2.0.0","2.0.1","2.0.2","2.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5355.json","vanir_signatures_modified":"2026-07-08T12:52:51Z","vanir_signatures":[{"source":"https://github.com/wireshark/wireshark/commit/5efb45231671baa2db2011d8f67f9d6e72bc455b","target":{"file":"wiretap/toshiba.c"},"deprecated":false,"digest":{"line_hashes":["222472030124558903662423588367175922458","195759074594662894182382324617615830295","283796853935284558832892467406390596183","109201914752022300569507316507146393595","277084973135359600370079367470878906833","208459913058928882533967903486234800560","288380669237646100572132430427755402934","71371983581895935206773910982285805940","5686293301648776978992919168810849288","336895237281205011077460297476857256315","228950723378601078918892079557320994569","87081937081611371651809983671600852229","157000304485411451266701731849443473487","172667033939294234761467952164003678289","105236842549951244178939431531586891643","43820112650451027626426710000672187177","326752506863499794459234409193910882951","36041466847695983854234170705769995075","68552537321264856197070472797328510024","75783356510037799163678349351110837102"],"threshold":0.9},"id":"CVE-2016-5355-430bec25","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"length":2479,"function_hash":"88309026750793822074938174147946152928"},"id":"CVE-2016-5355-44f1a51b","signature_type":"Function","signature_version":"v1","source":"https://github.com/wireshark/wireshark/commit/3270dfac43da861c714df76513456b46765ff47f","target":{"file":"wiretap/toshiba.c","function":"parse_toshiba_packet"}},{"digest":{"threshold":0.9,"line_hashes":["72302133209966418500491502823078993562","65751126460123115645082010701549214055","63620029592010607307553349671698053141","36968158628528279793305526355192498466","205212885502665659664724582713521958156","156545002709525894075805155748272119333","310550222594586872448747828688649468287","111081263017908559084416960774253831119","331820378455773273340130334246211456419","87081937081611371651809983671600852229","157000304485411451266701731849443473487","142717321117965291651073929275971677522","3893015500546448625981737174454852359","295760793327389517273004739152084809025"]},"id":"CVE-2016-5355-9f2be232","signature_type":"Line","signature_version":"v1","source":"https://github.com/wireshark/wireshark/commit/3270dfac43da861c714df76513456b46765ff47f","target":{"file":"wiretap/toshiba.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/wireshark/wireshark/commit/5efb45231671baa2db2011d8f67f9d6e72bc455b","target":{"file":"wiretap/toshiba.c","function":"parse_toshiba_packet"},"deprecated":false,"digest":{"function_hash":"45551249823097417350531750011362455708","length":2293},"id":"CVE-2016-5355-a6150e54"}]}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/wireshark/wireshark","events":[{"introduced":"4fab41a1f0e14e9124ea6a61e7bae42e95599495"},{"last_affected":"eed34f0ac6696c053585ddf75c5805b3d5b395cf"}],"database_specific":{"cpe":["cpe:2.3:a:wireshark:wireshark:1.12.0:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.1:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.2:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.3:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.4:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.5:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.6:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.7:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.8:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.9:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.10:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:1.12.11:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.2:*:*:*:*:*:*:*","cpe:2.3:a:wireshark:wireshark:2.0.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.12.0"},{"last_affected":"1.12.0"},{"introduced":"1.12.1"},{"last_affected":"1.12.1"},{"introduced":"1.12.2"},{"last_affected":"1.12.2"},{"introduced":"1.12.3"},{"last_affected":"1.12.3"},{"introduced":"1.12.4"},{"last_affected":"1.12.4"},{"introduced":"1.12.5"},{"last_affected":"1.12.5"},{"introduced":"1.12.6"},{"last_affected":"1.12.6"},{"introduced":"1.12.7"},{"last_affected":"1.12.7"},{"introduced":"1.12.8"},{"last_affected":"1.12.8"},{"introduced":"1.12.9"},{"last_affected":"1.12.9"},{"introduced":"1.12.10"},{"last_affected":"1.12.10"},{"introduced":"1.12.11"},{"last_affected":"1.12.11"},{"introduced":"2.0.0"},{"last_affected":"2.0.0"},{"introduced":"2.0.1"},{"last_affected":"2.0.1"},{"introduced":"2.0.2"},{"last_affected":"2.0.2"},{"introduced":"2.0.3"},{"last_affected":"2.0.3"}],"source":"CPE_STRING"}}],"versions":["1.12.0","1.12.1","1.12.10","1.12.11","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12.7","1.12.8","1.12.9","2.0.0","2.0.1","2.0.2","2.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5355.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}