PT-2017-11992 · Wireshark+2 · Wireshark+2
Publicado
2017-07-18
·
Atualizado
2019-10-03
·
CVE-2017-11410
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 2.0.0 through 2.0.13
Wireshark versions 2.2.0 through 2.2.7
Description
The WBXML dissector in Wireshark could enter an infinite loop due to packet injection or a malformed capture file. This issue arose from incomplete validation of the relationships between indexes and lengths, which was previously addressed in part but not fully resolved.
Recommendations
For Wireshark versions 2.0.0 through 2.0.13, update to a version that includes the fix for the infinite loop issue in the WBXML dissector.
For Wireshark versions 2.2.0 through 2.2.7, update to a version that includes the fix for the infinite loop issue in the WBXML dissector.
As a temporary workaround, consider avoiding the use of the WBXML dissector until a patched version is available.
Correção
RCE
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Wireshark