CVE-2017-6470: High severity Wireshark Wireshark vulnerability
Published Mar 4, 2017
·Updated
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.
Affected Software
3 affected components
Wireshark Wireshark>=2.0.0<=2.0.10
Wireshark Wireshark>=2.2.0<=2.2.4
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Mar 4, 2017
CVE Published
via MITRE·03:38 AM
Data Sourced
via MITRE·03:38 AM
Description
Data Sourced
via NVD·03:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6470?
CVE-2017-6470 is classified as a medium severity vulnerability that can lead to an infinite loop in Wireshark.
2
How do I fix CVE-2017-6470?
To fix CVE-2017-6470, upgrade Wireshark to versions 2.2.5 or higher, or 2.0.11 or higher.
3
Which versions of Wireshark are affected by CVE-2017-6470?
Versions 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10 of Wireshark are affected by CVE-2017-6470.
4
What causes the infinite loop in CVE-2017-6470?
The infinite loop in CVE-2017-6470 is triggered by packet injection or by a malformed capture file.
5
Is there any workaround for CVE-2017-6470?
There are no known workarounds for CVE-2017-6470; updating to a patched version is the only solution.