Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-9347NULL Pointer Dereference in Wireshark

Severity
7.5HIGHNVD
EPSS
5.0%
top 10.32%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 2
Latest updateMay 14

Description

In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.2.7-1 (bookworm)
Debianwireshark/wireshark< 2.2.7-1+3
NVDwireshark/wireshark2.2.02.2.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-59gv-v2r5-5289: In Wireshark 22022-05-14
OSV
CVE-2017-9347: In Wireshark 22017-06-02

💥Exploits & PoCs

1
Exploit-DB
Wireshark 2.2.0 < 2.2.12 - ROS Dissector Denial of Service2017-06-05

📋Vendor Advisories

2
Red Hat
wireshark: ROS dissector crash (wnpa-sec-2017-31)2017-06-01
Debian
CVE-2017-9347: wireshark - In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer d...2017

💬Community

2
Bugzilla
CVE-2017-11411 CVE-2017-9343 CVE-2017-9344 CVE-2017-9345 CVE-2017-9346 CVE-2017-9347 CVE-2017-9348 CVE-2017-9349 CVE-2017-9350 CVE-2017-9351 CVE-2017-9352 CVE-2017-9353 CVE-2017-9354 wireshark: variou2017-06-02
Bugzilla
CVE-2017-9347 wireshark: ROS dissector crash (wnpa-sec-2017-31)2017-06-02