CVE-2017-11407: Input Validation
Published Jul 18, 2017
·Updated
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.
Affected Software
3 affected components
Wireshark Wireshark>=2.0.0<=2.0.13
Wireshark Wireshark>=2.2.0<=2.2.7
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jul 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11407?
CVE-2017-11407 is categorized as a medium severity vulnerability due to the potential crash of the application.
2
How do I fix CVE-2017-11407?
To fix CVE-2017-11407, upgrade Wireshark to versions 2.2.8 or higher and 2.0.14 or higher.
3
Which versions of Wireshark are affected by CVE-2017-11407?
Wireshark versions 2.0.0 to 2.0.13 and 2.2.0 to 2.2.7 are affected by CVE-2017-11407.
4
What component of Wireshark is affected by CVE-2017-11407?
CVE-2017-11407 specifically affects the MQ dissector in Wireshark.
5
What impact does CVE-2017-11407 have on system stability?
CVE-2017-11407 can cause Wireshark to crash, potentially leading to loss of unsaved work or data.