CVE-2017-15193: High severity wireshark vulnerability
Published Oct 10, 2017
·Updated
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.
Affected Software
12 affected components
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Wireshark Wireshark=2.2.6
Wireshark Wireshark=2.2.7
Wireshark Wireshark=2.2.8
Wireshark Wireshark=2.2.9
Wireshark Wireshark=2.4.0
Wireshark Wireshark=2.4.1
Remediation
Patch Available
Event History
Oct 10, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15193?
CVE-2017-15193 has a medium severity rating due to the potential for crashes or memory exhaustion.
2
How do I fix CVE-2017-15193?
To fix CVE-2017-15193, upgrade Wireshark to version 2.4.2 or later.
3
What versions of Wireshark are affected by CVE-2017-15193?
CVE-2017-15193 affects Wireshark versions 2.2.0 to 2.2.9 and 2.4.0 to 2.4.1.
4
What issue does CVE-2017-15193 address in Wireshark?
CVE-2017-15193 addresses a flaw in the MBIM dissector that could lead to crashes or excessive memory use.
5
Who is responsible for addressing CVE-2017-15193?
The Wireshark development team is responsible for addressing CVE-2017-15193 through software updates.