CVE-2017-11408: Input Validation
Published Jul 18, 2017
·Updated
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for successful list dissection.
Affected Software
23 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Wireshark Wireshark=2.0.5
Wireshark Wireshark=2.0.6
Wireshark Wireshark=2.0.7
Wireshark Wireshark=2.0.8
Wireshark Wireshark=2.0.9
Wireshark Wireshark=2.0.10
Wireshark Wireshark=2.0.11
Wireshark Wireshark=2.0.12
Wireshark Wireshark=2.0.13
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Wireshark Wireshark=2.2.6
Wireshark Wireshark=2.2.7
Remediation
Patch Available
Event History
Jul 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11408?
CVE-2017-11408 is considered a medium-severity vulnerability due to the potential for crashes of the AMQP dissector in Wireshark.
2
How do I fix CVE-2017-11408?
To fix CVE-2017-11408, upgrade to Wireshark versions 2.2.8, 2.4.0, or later to address the issues in the AMQP dissector.
3
Which versions of Wireshark are affected by CVE-2017-11408?
CVE-2017-11408 affects Wireshark versions 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13.
4
What components are vulnerable in CVE-2017-11408?
The AMQP dissector in Wireshark is the component vulnerable in CVE-2017-11408, leading to possible crashes.
5
Is there a workaround for CVE-2017-11408?
There is no specific workaround recommended for CVE-2017-11408; updating to a patched version is advised.