CVE-2017-15191Use of Externally-Controlled Format String in Wireshark

Severity
7.5HIGHNVD
EPSS
0.9%
top 23.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 14

Description

In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.2-1 (bookworm)
Debianwireshark/wireshark< 2.4.2-1+3
NVDwireshark/wireshark2.0.02.0.15+2

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rmxr-5w24-74wc: In Wireshark 22022-05-14
OSV
CVE-2017-15191: In Wireshark 22017-10-10

📋Vendor Advisories

2
Red Hat
wireshark: DMP dissector crash2017-10-10
Debian
CVE-2017-15191: wireshark - In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissec...2017

💬Community

2
Bugzilla
CVE-2017-15191 wireshark: DMP dissector crash2017-10-11
Bugzilla
CVE-2017-15189 CVE-2017-15190 CVE-2017-15191 CVE-2017-15192 CVE-2017-15193 wireshark: various flaws [fedora-all]2017-10-11