CVE-2017-9347: Null Pointer Dereference
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.
Affected Software
1 affected component
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9347?
CVE-2017-9347 has been classified with a high severity rating due to the potential for crashing the Wireshark application.
2
How do I fix CVE-2017-9347?
To fix CVE-2017-9347, upgrade Wireshark to version 2.2.7 or later, where the issue has been addressed.
3
Which versions of Wireshark are affected by CVE-2017-9347?
Wireshark versions 2.2.0 through 2.2.6 are affected by CVE-2017-9347.
4
What happens if I don't address CVE-2017-9347?
Failing to address CVE-2017-9347 may result in system instability and crashes while using Wireshark.
5
Is there any workaround for CVE-2017-9347?
There are no known workarounds for CVE-2017-9347; the recommended action is to update Wireshark.