PT-2017-11992 · Wireshark+2 · Wireshark+2
Published
2017-07-18
·
Updated
2019-10-03
·
CVE-2017-11410
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 2.0.0 through 2.0.13
Wireshark versions 2.2.0 through 2.2.7
Description
The WBXML dissector in Wireshark could enter an infinite loop due to packet injection or a malformed capture file. This issue arose from incomplete validation of the relationships between indexes and lengths, which was previously addressed in part but not fully resolved.
Recommendations
For Wireshark versions 2.0.0 through 2.0.13, update to a version that includes the fix for the infinite loop issue in the WBXML dissector.
For Wireshark versions 2.2.0 through 2.2.7, update to a version that includes the fix for the infinite loop issue in the WBXML dissector.
As a temporary workaround, consider avoiding the use of the WBXML dissector until a patched version is available.
Fix
RCE
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Wireshark