CVE-2017-9766Uncontrolled Recursion in Wireshark

Severity
7.5HIGHNVD
EPSS
0.9%
top 24.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 21
Latest updateMay 13

Description

In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 2.4.0-1 (bookworm)
Debianwireshark/wireshark< 2.4.0-1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4v8g-w2m4-45p8: In Wireshark 22022-05-13
OSV
CVE-2017-9766: In Wireshark 22017-06-21

📋Vendor Advisories

2
Red Hat
wireshark: PROFINET IO data with a high recursion depth can cause stack exhaustion2017-06-19
Debian
CVE-2017-9766: wireshark - In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote a...2017

💬Community

2
Bugzilla
CVE-2017-9616 CVE-2017-9617 CVE-2017-9766 wireshark: various flaws [fedora-all]2017-06-22
Bugzilla
CVE-2017-9766 wireshark: PROFINET IO data with a high recursion depth can cause stack exhaustion2017-06-22