PT-2017-14699 · Wireshark+2 · Wireshark+2

Published

2017-12-01

·

Updated

2024-06-15

·

CVE-2017-17083

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.2.0 through 2.2.10 Wireshark versions 2.4.0 through 2.4.2
Description The issue concerns a potential crash in the NetBIOS dissector. This was resolved by modifying the epan/dissectors/packet-netbios.c file to ensure that write operations are properly bounded within a buffer, preventing a crash.
Recommendations For Wireshark versions 2.2.0 through 2.2.10, update to a version where the epan/dissectors/packet-netbios.c file has been modified to include bounds checking for write operations. For Wireshark versions 2.4.0 through 2.4.2, update to a version where the epan/dissectors/packet-netbios.c file has been modified to include bounds checking for write operations.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2780
ALT-PU-2018-2487
CVE-2017-17083
DLA-1226-1
DSA-4060-1
MGASA-2017-0445
OPENSUSE-SU-2024:11513-1
SUSE-SU-2017:3436-1
SUSE-SU-2017_3436-1
SUSE-SU-2018:0054-1

Affected Products

Alt Linux
Suse
Wireshark