CVE-2017-15189: High severity wireshark vulnerability
Published Oct 10, 2017
·Updated
In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by adding decrements.
Affected Software
2 affected components
Wireshark Wireshark=2.4.0
Wireshark Wireshark=2.4.1
Remediation
Patch Available
Event History
Oct 10, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15189?
CVE-2017-15189 has a moderate severity level due to the potential for an infinite loop impacting performance.
2
How do I fix CVE-2017-15189?
To fix CVE-2017-15189, upgrade to Wireshark version 2.4.2 or later where the issue has been addressed.
3
What does CVE-2017-15189 affect?
CVE-2017-15189 affects Wireshark versions 2.4.0 and 2.4.1 specifically through the DOCSIS dissector.
4
Can CVE-2017-15189 cause system crashes?
While CVE-2017-15189 may not cause crashes, it can lead to freezing and unresponsiveness during packet analysis.
5
Is CVE-2017-15189 a known issue in earlier versions of Wireshark?
Yes, CVE-2017-15189 is a known issue specifically in Wireshark versions 2.4.0 and 2.4.1.