CVE-2017-15190: High severity wireshark vulnerability
Published Oct 10, 2017
·Updated
In Wireshark 2.4.0 to 2.4.1, the RTSP dissector could crash. This was addressed in epan/dissectors/packet-rtsp.c by correcting the scope of a variable.
Affected Software
2 affected components
Wireshark Wireshark=2.4.0
Wireshark Wireshark=2.4.1
Remediation
Patch Available
Event History
Oct 10, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15190?
CVE-2017-15190 has a low severity rating as it results in a crash in Wireshark but does not allow remote code execution.
2
How do I fix CVE-2017-15190?
To fix CVE-2017-15190, update to Wireshark version 2.4.2 or later where this vulnerability is addressed.
3
Which versions of Wireshark are affected by CVE-2017-15190?
CVE-2017-15190 affects Wireshark versions 2.4.0 and 2.4.1.
4
What type of vulnerability is CVE-2017-15190?
CVE-2017-15190 is a denial of service vulnerability caused by an issue in the RTSP dissector.
5
Is there a workaround for CVE-2017-15190?
There is no official workaround for CVE-2017-15190, so it is recommended to upgrade to a secure version.