CVE-2017-7700Infinite Loop in Wireshark

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 13

Description

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.2.6+g32dac6a-1 (bookworm)
Debianwireshark/wireshark< 2.2.6+g32dac6a-1+3
NVDwireshark/wireshark2.0.02.0.11+1

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pwc9-q2gc-2rch: In Wireshark 22022-05-13
OSV
CVE-2017-7700: In Wireshark 22017-04-12

📋Vendor Advisories

4
Cisco
Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability2017-11-29
Red Hat
wireshark: NetScaler file parser infinite loop (wnpa-sec-2017-14)2017-04-12
Debian
CVE-2017-7700: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could...2017
Cisco
Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability

💬Community

2
Bugzilla
CVE-2017-7700 wireshark: NetScaler file parser infinite loop (wnpa-sec-2017-14)2017-04-13
Bugzilla
CVE-2017-11410 CVE-2017-7700 CVE-2017-7701 CVE-2017-7702 CVE-2017-7703 CVE-2017-7704 CVE-2017-7705 CVE-2017-7745 CVE-2017-7746 CVE-2017-7747 CVE-2017-7748 wireshark: various flaws [fedora-all]2017-04-13