CVE-2017-9344: Divide by Zero
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.
Affected Software
3 affected components
Wireshark Wireshark>=2.0.0<=2.0.12
Wireshark Wireshark>=2.2.0<=2.2.6
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9344?
CVE-2017-9344 has a medium severity rating due to potential denial of service caused by a division by zero error.
2
How do I fix CVE-2017-9344?
To fix CVE-2017-9344, update Wireshark to version 2.2.7 or later, or to version 2.0.13 or later.
3
What versions of Wireshark are affected by CVE-2017-9344?
CVE-2017-9344 affects Wireshark versions 2.2.0 through 2.2.6 and 2.0.0 through 2.0.12.
4
Does CVE-2017-9344 affect Debian users?
Yes, CVE-2017-9344 impacts Debian GNU/Linux 8.0 users if they are using the affected versions of Wireshark.
5
What is the nature of the vulnerability in CVE-2017-9344?
CVE-2017-9344 is a vulnerability in the Bluetooth L2CAP dissector that can lead to a crash due to a divide by zero error.