PT-2017-17924 · Wireshark+2 · Wireshark+2

Published

2017-04-12

·

Updated

2024-06-15

·

CVE-2017-7747

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.0.0 through 2.0.11 Wireshark versions 2.2.0 through 2.2.5
Description The issue is related to the PacketBB dissector, which could crash due to packet injection or a malformed capture file. This crash was triggered by uncontrolled additions to the protocol tree.
Recommendations For Wireshark versions 2.0.0 through 2.0.11, update to a version where the issue is fixed by restricting additions to the protocol tree in epan/dissectors/packet-packetbb.c. For Wireshark versions 2.2.0 through 2.2.5, update to a version where the issue is fixed by restricting additions to the protocol tree in epan/dissectors/packet-packetbb.c.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1470
CVE-2017-7747
DLA-1634-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2017:1174-1
SUSE-SU-2017:1442-1

Affected Products

Alt Linux
Suse
Wireshark