CVE-2017-6471: Input Validation
Published Mar 4, 2017
·Updated
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length.
Affected Software
3 affected components
Wireshark Wireshark>=2.0.0<=2.0.10
Wireshark Wireshark>=2.2.0<=2.2.4
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Mar 4, 2017
CVE Published
via MITRE·03:38 AM
Data Sourced
via MITRE·03:38 AM
Description
Data Sourced
via NVD·03:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6471?
CVE-2017-6471 is classified as a medium severity vulnerability due to its potential to cause an infinite loop in Wireshark.
2
How do I fix CVE-2017-6471?
To fix CVE-2017-6471, update Wireshark to version 2.2.5 or later, or 2.0.11 or later.
3
What software versions are affected by CVE-2017-6471?
CVE-2017-6471 affects Wireshark versions 2.0.0 to 2.0.10 and 2.2.0 to 2.2.4.
4
What types of attacks can exploit CVE-2017-6471?
CVE-2017-6471 can be exploited through the injection of packets or by using malformed capture files.
5
What is the impact of CVE-2017-6471 on affected systems?
The impact of CVE-2017-6471 can lead to application crashes and denial of service for users running affected versions of Wireshark.