CVE-2017-11410Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
0.3%
top 50.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 13

Description

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding validation of the relationships between indexes and lengths. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-7702.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.0-1 (bookworm)
Debianwireshark/wireshark< 2.4.0-1+3
NVDwireshark/wireshark22 versions+21

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x5hh-chcp-7jv5: In Wireshark through 22022-05-13
OSV
CVE-2017-11410: In Wireshark through 22017-07-18

📋Vendor Advisories

2
Red Hat
wireshark: WBXML dissector infinite loop (wnpa-sec-2017-13)2017-04-12
Debian
CVE-2017-11410: wireshark - In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could g...2017

💬Community

2
Bugzilla
CVE-2017-11410 CVE-2017-7700 CVE-2017-7701 CVE-2017-7702 CVE-2017-7703 CVE-2017-7704 CVE-2017-7705 CVE-2017-7745 CVE-2017-7746 CVE-2017-7747 CVE-2017-7748 wireshark: various flaws [fedora-all]2017-04-13
Bugzilla
CVE-2017-7702 CVE-2017-11410 wireshark: WBXML dissector infinite loop (wnpa-sec-2017-13)2017-04-13