The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
http://lists.opensuse.org/opensuse-updates/2016-03/msg00015.html
http://lists.opensuse.org/opensuse-updates/2016-03/msg00016.html
http://www.debian.org/security/2016/dsa-3516
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securitytracker.com/id/1035118
http://www.wireshark.org/security/wnpa-sec-2016-03.html
Source: MITRE
Published: 2016-02-28
Updated: 2017-09-08
Type: CWE-399
Base Score: 7.1
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
Impact Score: 6.9
Exploitability Score: 8.6
Severity: HIGH
Base Score: 5.9
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.2
Severity: MEDIUM