CVE-2017-7703: High severity Wireshark Wireshark vulnerability
Published Apr 12, 2017
·Updated
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.
Affected Software
19 affected components
Wireshark Wireshark=2.0.0
Wireshark Wireshark=2.0.1
Wireshark Wireshark=2.0.2
Wireshark Wireshark=2.0.3
Wireshark Wireshark=2.0.4
Wireshark Wireshark=2.0.5
Wireshark Wireshark=2.0.6
Wireshark Wireshark=2.0.7
Wireshark Wireshark=2.0.8
Wireshark Wireshark=2.0.9
Wireshark Wireshark=2.0.10
Wireshark Wireshark=2.0.11
Wireshark Wireshark=2.2.0
Wireshark Wireshark=2.2.1
Wireshark Wireshark=2.2.2
Wireshark Wireshark=2.2.3
Wireshark Wireshark=2.2.4
Wireshark Wireshark=2.2.5
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Apr 12, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What versions of Wireshark are affected by CVE-2017-7703?
Wireshark versions 2.0.0 to 2.0.11 and 2.2.0 to 2.2.5 are affected by CVE-2017-7703.
2
What is the impact of CVE-2017-7703 on Wireshark?
CVE-2017-7703 can cause the IMAP dissector to crash when triggered by packet injection or a malformed capture file.
3
How can I fix CVE-2017-7703 in Wireshark?
To fix CVE-2017-7703, update Wireshark to a version later than 2.2.5 or 2.0.11.
4
Has CVE-2017-7703 been addressed in any security updates?
Yes, CVE-2017-7703 has been addressed in later versions of Wireshark through a fix in the IMAP dissector.
5
Is CVE-2017-7703 related to any other vulnerabilities in Wireshark?
CVE-2017-7703 is specific to the IMAP dissector; however, similar issues can arise with other dissectors if not properly handled.