CVE-2017-9343: Null Pointer Dereference
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.
Affected Software
2 affected components
Wireshark Wireshark>=2.0.0<=2.0.12
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9343?
CVE-2017-9343 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-9343?
To fix CVE-2017-9343, update Wireshark to version 2.2.7 or later, or 2.0.13 or later.
3
What versions of Wireshark are affected by CVE-2017-9343?
CVE-2017-9343 affects Wireshark versions 2.0.0 to 2.0.12 and 2.2.0 to 2.2.6.
4
What type of vulnerability is CVE-2017-9343?
CVE-2017-9343 is a null pointer dereference vulnerability found in the MSNIP dissector.
5
Is there any exploit associated with CVE-2017-9343?
There are no public exploits specifically associated with CVE-2017-9343 as of now.