CVE-2017-7747Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
2.0%
top 16.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 14

Description

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.2.6+g32dac6a-1 (bookworm)
Debianwireshark/wireshark< 2.2.6+g32dac6a-1+3
NVDwireshark/wireshark18 versions+17

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ggp4-5297-vv47: In Wireshark 22022-05-14
OSV
CVE-2017-7747: In Wireshark 22017-04-12

📋Vendor Advisories

2
Red Hat
wireshark: PacketBB dissector crash (wnpa-sec-2017-18)2017-04-12
Debian
CVE-2017-7747: wireshark - In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could cr...2017

💬Community

2
Bugzilla
CVE-2017-7747 wireshark: PacketBB dissector crash (wnpa-sec-2017-18)2017-04-13
Bugzilla
CVE-2017-11410 CVE-2017-7700 CVE-2017-7701 CVE-2017-7702 CVE-2017-7703 CVE-2017-7704 CVE-2017-7705 CVE-2017-7745 CVE-2017-7746 CVE-2017-7747 CVE-2017-7748 wireshark: various flaws [fedora-all]2017-04-13