CVE-2017-6467: High severity Wireshark Wireshark vulnerability
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by changing the restrictions on file size.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Upgrade/patch Wireshark so that in wiretap/netscaler.c the file size restrictions for the Netscaler file parser are changed to prevent the infinite loop triggered by malformed capture files.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6467?
CVE-2017-6467 has been classified as a moderate severity vulnerability.
How do I fix CVE-2017-6467?
To address CVE-2017-6467, update Wireshark to a version above 2.2.4 or 2.0.10.
What systems are affected by CVE-2017-6467?
CVE-2017-6467 affects Wireshark versions 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10.
What type of vulnerability is CVE-2017-6467?
CVE-2017-6467 is an infinite loop vulnerability triggered by a malformed capture file.
Is there a workaround for CVE-2017-6467?
There is no confirmed workaround for CVE-2017-6467; updating the software is the recommended solution.