CVE-2017-13767Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
0.3%
top 44.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateMay 13

Description

In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.1-1 (bookworm)
Debianwireshark/wireshark< 2.4.1-1+3
NVDwireshark/wireshark23 versions+22

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w6c6-qjcr-rfwc: In Wireshark 22022-05-13
OSV
CVE-2017-13767: In Wireshark 22017-08-30

📋Vendor Advisories

2
Red Hat
wireshark: MSDP dissector infinite loop (wnpa-sec-2017-38)2017-08-29
Debian
CVE-2017-13767: wireshark - In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector coul...2017

💬Community

2
Bugzilla
CVE-2017-13765 CVE-2017-13766 CVE-2017-13767 wireshark: various flaws [fedora-all]2017-08-30
Bugzilla
CVE-2017-13767 wireshark: MSDP dissector infinite loop (wnpa-sec-2017-38)2017-08-30