CVE-2017-6474: High severity Wireshark Wireshark vulnerability
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6474?
CVE-2017-6474 has been classified as a medium severity vulnerability due to the potential for denial of service via an infinite loop.
How do I fix CVE-2017-6474?
To fix CVE-2017-6474, you should upgrade Wireshark to the latest version, ensuring that you are beyond versions 2.2.4 or 2.0.10.
What software versions are affected by CVE-2017-6474?
CVE-2017-6474 affects Wireshark versions from 2.0.0 to 2.0.10 and 2.2.0 to 2.2.4.
Can CVE-2017-6474 be exploited remotely?
The exploitation of CVE-2017-6474 requires a user to open a specially crafted capture file, making it more of a local attack vector.
What mitigation strategies exist for CVE-2017-6474?
Mitigation for CVE-2017-6474 involves ensuring that users are trained not to open untrusted capture files and keeping Wireshark updated.