PT-2017-18864 · Wireshark+2 · Wireshark+2

Published

2017-06-02

·

Updated

2024-06-15

·

CVE-2017-9351

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.0.0 through 2.0.12 Wireshark versions 2.2.0 through 2.2.6
Description The issue is related to the DHCP dissector, which could read past the end of a buffer. This was addressed by extracting the Vendor Class Identifier more carefully in the file epan/dissectors/packet-bootp.c.
Recommendations For Wireshark versions 2.0.0 through 2.0.12, update to a version where the DHCP dissector issue is fixed. For Wireshark versions 2.2.0 through 2.2.6, update to a version where the DHCP dissector issue is fixed.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1689
ALT-PU-2018-2487
CVE-2017-9351
MGASA-2017-0161
OPENSUSE-SU-2024:11513-1
SUSE-SU-2017:1663-1
SUSE-SU-2017:1664-1

Affected Products

Alt Linux
Suse
Wireshark