CVE-2017-9350: Input Validation
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.
Affected Software
2 affected components
Wireshark Wireshark>=2.0.0<=2.0.12
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9350?
CVE-2017-9350 has been classified as a medium severity vulnerability due to potential crashes and memory exhaustion.
2
How do I fix CVE-2017-9350?
To fix CVE-2017-9350, upgrade Wireshark to a version later than 2.2.6 or 2.0.12 that includes the necessary patches.
3
What are the affected versions of Wireshark for CVE-2017-9350?
CVE-2017-9350 affects Wireshark versions 2.0.0 to 2.0.12 and 2.2.0 to 2.2.6.
4
What kind of issues does CVE-2017-9350 cause in Wireshark?
CVE-2017-9350 can cause crashes or exhaust system memory when using the openSAFETY dissector.
5
Is there a workaround for CVE-2017-9350?
The best approach to mitigate CVE-2017-9350 is to update to a patched version of Wireshark since no specific workaround is available.