CVE-2017-15192: High severity wireshark vulnerability
Published Oct 10, 2017
·Updated
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.
Affected Software
12 affected components
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Wireshark Wireshark=2.2.6
Wireshark Wireshark=2.2.7
Wireshark Wireshark=2.2.8
Wireshark Wireshark=2.2.9
Wireshark Wireshark=2.4.0
Wireshark Wireshark=2.4.1
Remediation
Patch Available
Event History
Oct 10, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15192?
CVE-2017-15192 is considered a moderate severity vulnerability due to the potential for the BT ATT dissector to crash.
2
How do I fix CVE-2017-15192?
To mitigate CVE-2017-15192, upgrade to Wireshark versions 2.4.2 or later, or 2.2.10 or later.
3
Which versions of Wireshark are affected by CVE-2017-15192?
Wireshark versions 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9 are affected by CVE-2017-15192.
4
What component does CVE-2017-15192 impact in Wireshark?
CVE-2017-15192 impacts the BT ATT dissector component in Wireshark.
5
What happens if CVE-2017-15192 is exploited?
Exploitation of CVE-2017-15192 could lead to a denial-of-service condition by crashing the application.