CVE-2017-9351: Buffer Overflow
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully.
Affected Software
2 affected components
Wireshark Wireshark>=2.0.0<=2.0.12
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9351?
CVE-2017-9351 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-9351?
To fix CVE-2017-9351, upgrade Wireshark to version 2.2.7 or later if you are using the 2.2.x series, or to version 2.0.13 or later if you are using the 2.0.x series.
3
Which versions of Wireshark are affected by CVE-2017-9351?
Wireshark versions from 2.0.0 to 2.0.12 and from 2.2.0 to 2.2.6 are affected by CVE-2017-9351.
4
What type of vulnerability is CVE-2017-9351?
CVE-2017-9351 is a buffer overflow vulnerability in the DHCP dissector of Wireshark.
5
Who is impacted by CVE-2017-9351?
Users of affected versions of Wireshark who analyze DHCP packets could be impacted by CVE-2017-9351.