CVE-2017-9352: High severity Wireshark Wireshark vulnerability
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by ensuring that backwards parsing cannot occur.
Affected Software
2 affected components
Wireshark Wireshark>=2.0.0<=2.0.12
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9352?
CVE-2017-9352 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2017-9352?
To fix CVE-2017-9352, upgrade Wireshark to version 2.2.7 or later, or 2.0.13 or later.
3
What versions of Wireshark are affected by CVE-2017-9352?
CVE-2017-9352 affects Wireshark versions 2.0.0 to 2.0.12 and 2.2.0 to 2.2.6.
4
What is the impact of CVE-2017-9352?
The vulnerability can cause Wireshark to enter an infinite loop, potentially leading to a denial of service.
5
Who discovered CVE-2017-9352?
CVE-2017-9352 was reported by security researchers analyzing the Bazaar dissector in Wireshark.