CVE-2017-11411: Input Validation
Published Jul 18, 2017
·Updated
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.
Affected Software
22 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Wireshark Wireshark=2.0.5
Wireshark Wireshark=2.0.6
Wireshark Wireshark=2.0.7
Wireshark Wireshark=2.0.8
Wireshark Wireshark=2.0.9
Wireshark Wireshark=2.0.10
Wireshark Wireshark=2.0.11
Wireshark Wireshark=2.0.12
Wireshark Wireshark=2.0.13
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Wireshark Wireshark=2.2.6
Wireshark Wireshark=2.2.7
Remediation
Patch Available
Event History
Jul 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11411?
CVE-2017-11411 has a severity rating that can lead to application crashes or excessive memory consumption.
2
How do I fix CVE-2017-11411?
To fix CVE-2017-11411, upgrade Wireshark to version 2.2.8 or later, or version 2.0.14 or later.
3
What versions of Wireshark are affected by CVE-2017-11411?
Wireshark versions 2.0.0 to 2.0.13 and 2.2.0 to 2.2.7 are affected by CVE-2017-11411.
4
What type of vulnerability is CVE-2017-11411?
CVE-2017-11411 is a denial-of-service vulnerability caused by the openSAFETY dissector.
5
Is CVE-2017-11411 related to any other vulnerabilities?
Yes, CVE-2017-11411 is associated with an incomplete fix for CVE-2017-9350.