First published: Tue Jul 18 2017(Updated: )
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=2.0.0<=2.0.13 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11409 is considered a medium severity vulnerability due to the potential for denial of service.
To fix CVE-2017-11409, update Wireshark to version 2.0.14 or later.
CVE-2017-11409 affects Wireshark versions from 2.0.0 to 2.0.13 and Debian GNU/Linux 8.0.
CVE-2017-11409 is a denial-of-service vulnerability in the GPRS LLC dissector of Wireshark.
CVE-2017-11409 primarily leads to denial of service and does not result in data compromise.