CVE-2017-9350Improper Input Validation in Wireshark

Severity
7.5HIGHNVD
EPSS
1.0%
top 23.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 2
Latest updateMay 13

Description

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.0-1 (bookworm)+1
Debianwireshark/wireshark< 2.2.7-1+7
NVDwireshark/wireshark2.0.02.0.12+23

Patches

🔴Vulnerability Details

4
GHSA
GHSA-3g9v-2x9v-4j4g: In Wireshark through 22022-05-13
GHSA
GHSA-7g7x-q86m-jm5c: In Wireshark 22022-05-13
OSV
CVE-2017-11411: In Wireshark through 22017-07-18
OSV
CVE-2017-9350: In Wireshark 22017-06-02

📋Vendor Advisories

4
Red Hat
wireshark: openSAFETY dissector memory exhaustion (wnpa-sec-2017-28)2017-06-01
Red Hat
wireshark: openSAFETY dissector memory exhaustion (wnpa-sec-2017-28)2017-06-01
Debian
CVE-2017-11411: wireshark - In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector co...2017
Debian
CVE-2017-9350: wireshark - In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could ...2017

💬Community

2
Bugzilla
CVE-2017-11411 CVE-2017-9343 CVE-2017-9344 CVE-2017-9345 CVE-2017-9346 CVE-2017-9347 CVE-2017-9348 CVE-2017-9349 CVE-2017-9350 CVE-2017-9351 CVE-2017-9352 CVE-2017-9353 CVE-2017-9354 wireshark: variou2017-06-02
Bugzilla
CVE-2017-9350 CVE-2017-11411 wireshark: openSAFETY dissector memory exhaustion (wnpa-sec-2017-28)2017-06-02