CVE-2017-6014: High severity Wireshark Wireshark vulnerability
Published Feb 17, 2017
·Updated
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory.
Affected Software
2 affected components
Wireshark Wireshark<=2.2.4
Debian Debian Linux=8.0
Event History
Feb 17, 2017
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
Description
Data Sourced
via NVD·07:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6014?
CVE-2017-6014 has a high severity rating due to its potential for memory exhaustion and denial of service.
2
How do I fix CVE-2017-6014?
To fix CVE-2017-6014, you should update Wireshark to version 2.2.5 or later.
3
What types of files are exploited in CVE-2017-6014?
CVE-2017-6014 is exploited through malformed STANAG 4607 capture files.
4
Which versions of Wireshark are affected by CVE-2017-6014?
Wireshark versions 2.2.4 and earlier are affected by CVE-2017-6014.
5
Does CVE-2017-6014 affect any other operating systems?
Yes, CVE-2017-6014 also affects Debian GNU/Linux 8.0 but primarily targets Wireshark software.