CVE-2017-9348: Buffer Overflow
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value.
Affected Software
1 affected component
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9348?
CVE-2017-9348 has been classified as a medium severity vulnerability due to potential buffer over-read issues.
2
How do I fix CVE-2017-9348?
To fix CVE-2017-9348, update Wireshark to version 2.2.7 or later.
3
What software versions are affected by CVE-2017-9348?
CVE-2017-9348 affects Wireshark versions 2.2.0 to 2.2.6.
4
What type of vulnerability is CVE-2017-9348?
CVE-2017-9348 is a buffer over-read vulnerability in the DOF dissector of Wireshark.
5
Is CVE-2017-9348 exploitable in a network environment?
CVE-2017-9348 can potentially be exploited when processing crafted DOF packets, leading to information disclosure.