CVE-2017-13764: Null Pointer Dereference
Published Aug 30, 2017
·Updated
In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/packet-mbtcp.c by adding length validation.
Affected Software
1 affected component
Wireshark Wireshark=2.4.0
Remediation
Patch Available
Event History
Aug 30, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13764?
CVE-2017-13764 has been classified as a high severity vulnerability due to the potential for application crashes.
2
How does CVE-2017-13764 affect Wireshark?
CVE-2017-13764 affects Wireshark version 2.4.0, allowing a NULL pointer dereference in the Modbus dissector.
3
How do I fix CVE-2017-13764?
To fix CVE-2017-13764, users should upgrade to the latest version of Wireshark that addresses this vulnerability.
4
What version of Wireshark is vulnerable to CVE-2017-13764?
Wireshark version 2.4.0 is vulnerable to CVE-2017-13764.
5
What type of vulnerability is CVE-2017-13764?
CVE-2017-13764 is a NULL pointer dereference vulnerability found in the Modbus dissector of Wireshark.