First published: Sat Dec 30 2017(Updated: )
In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | <=2.2.11 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17997 is considered a moderate severity vulnerability as it can lead to a crash of the Wireshark application.
To fix CVE-2017-17997, you should upgrade Wireshark to version 2.2.12 or later.
Wireshark versions prior to 2.2.12, specifically up to 2.2.11, are affected by CVE-2017-17997.
CVE-2017-17997 affects Wireshark on multiple operating systems, including Debian GNU/Linux version 8.0.
CVE-2017-17997 involves a NULL pointer misuse in the MRDISC dissector leading to potential application crashes.