CVE-2017-7701: High severity Wireshark Wireshark vulnerability
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-bgp.c by using a different integer data type.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7701?
CVE-2017-7701 has been assigned a severity rating of medium due to its potential for causing resource exhaustion through an infinite loop.
How do I fix CVE-2017-7701?
To fix CVE-2017-7701, upgrade to Wireshark version 2.2.6 or later, or 2.0.12 or later, where the vulnerability has been addressed.
Which versions of Wireshark are affected by CVE-2017-7701?
CVE-2017-7701 affects Wireshark versions 2.0.0 to 2.0.11 and 2.2.0 to 2.2.5.
What can trigger the vulnerability in CVE-2017-7701?
CVE-2017-7701 can be triggered by packet injection or by using a malformed capture file during analysis.
Is CVE-2017-7701 an exploit that hackers can easily use?
While CVE-2017-7701 is a denial of service vulnerability, it requires specific malformed input to exploit, making it less likely to be used in general attacks.