CVE-2017-13767: Input Validation
Published Aug 30, 2017
·Updated
In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.
Affected Software
23 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Wireshark Wireshark=2.0.5
Wireshark Wireshark=2.0.6
Wireshark Wireshark=2.0.7
Wireshark Wireshark=2.0.8
Wireshark Wireshark=2.0.9
Wireshark Wireshark=2.0.10
Wireshark Wireshark=2.0.11
Wireshark Wireshark=2.0.12
Wireshark Wireshark=2.0.13
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Wireshark Wireshark=2.2.6
Wireshark Wireshark=2.2.7
Wireshark Wireshark=2.4.0
Remediation
Patch Available
Event History
Aug 30, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13767?
The severity of CVE-2017-13767 is rated as medium due to the potential for an infinite loop causing denial of service.
2
How do I fix CVE-2017-13767?
To fix CVE-2017-13767, update to Wireshark versions 2.4.1, 2.2.9, or 2.0.15, where the vulnerability has been resolved.
3
Which versions of Wireshark are affected by CVE-2017-13767?
CVE-2017-13767 affects Wireshark versions 2.0.0 to 2.0.14, 2.2.0 to 2.2.8, and 2.4.0.
4
What type of vulnerability is CVE-2017-13767?
CVE-2017-13767 is a denial of service vulnerability due to an infinite loop within the MSDP dissector.
5
Is CVE-2017-13767 being actively exploited?
There is no current evidence that CVE-2017-13767 is being actively exploited, but updating is recommended to prevent potential issues.