CVE-2017-5597: Integer Overflow
Published Jan 25, 2017
·Updated
In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dhcpv6.c by changing a data type to avoid an integer overflow.
Affected Software
14 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Wireshark Wireshark=2.0.5
Wireshark Wireshark=2.0.6
Wireshark Wireshark=2.0.7
Wireshark Wireshark=2.0.8
Wireshark Wireshark=2.0.9
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Remediation
Patch Available
Patch Available
Event History
Jan 25, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5597?
CVE-2017-5597 is considered a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2017-5597?
To fix CVE-2017-5597, upgrade Wireshark to version 2.2.4 or later, or 2.0.10 or later.
3
What versions of Wireshark are affected by CVE-2017-5597?
CVE-2017-5597 affects Wireshark versions 2.0.0 to 2.0.9 and 2.2.0 to 2.2.3.
4
What type of attack does CVE-2017-5597 involve?
CVE-2017-5597 involves a potential denial of service through packet injection or malformed capture files.
5
What is the impact of CVE-2017-5597 on system stability?
CVE-2017-5597 can cause Wireshark to enter a large loop, significantly impacting system stability.