CVE-2017-11409: High severity Wireshark Wireshark vulnerability
Published Jul 18, 2017
·Updated
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
Affected Software
2 affected components
Wireshark Wireshark>=2.0.0<=2.0.13
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jul 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11409?
CVE-2017-11409 is considered a medium severity vulnerability due to the potential for denial of service.
2
How do I fix CVE-2017-11409?
To fix CVE-2017-11409, update Wireshark to version 2.0.14 or later.
3
What software is affected by CVE-2017-11409?
CVE-2017-11409 affects Wireshark versions from 2.0.0 to 2.0.13 and Debian GNU/Linux 8.0.
4
What type of vulnerability is CVE-2017-11409?
CVE-2017-11409 is a denial-of-service vulnerability in the GPRS LLC dissector of Wireshark.
5
Can CVE-2017-11409 lead to data compromise?
CVE-2017-11409 primarily leads to denial of service and does not result in data compromise.