PT-2017-17925 · Wireshark+2 · Wireshark+2

Jakub Zawadzki

·

Published

2017-04-12

·

Updated

2024-06-15

·

CVE-2017-7748

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.0.0 through 2.0.11 Wireshark versions 2.2.0 through 2.2.5
Description The issue arises from the WSP dissector potentially entering an infinite loop. This can be triggered by either packet injection or a malformed capture file.
Recommendations For Wireshark versions 2.0.0 through 2.0.11, update to a version where the length check has been added to epan/dissectors/packet-wsp.c to prevent the infinite loop. For Wireshark versions 2.2.0 through 2.2.5, update to a version where the length check has been added to epan/dissectors/packet-wsp.c to prevent the infinite loop.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1470
CVE-2017-7748
OPENSUSE-SU-2024:11513-1
SUSE-SU-2017:1174-1
SUSE-SU-2017:1442-1

Affected Products

Alt Linux
Suse
Wireshark