CVE-2017-9353: Input Validation
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.
Affected Software
1 affected component
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9353?
CVE-2017-9353 has been rated as a medium severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2017-9353?
To fix CVE-2017-9353, upgrade Wireshark to version 2.2.7 or later.
3
What software versions are affected by CVE-2017-9353?
CVE-2017-9353 affects Wireshark versions from 2.2.0 to 2.2.6.
4
Who discovered the vulnerability CVE-2017-9353?
CVE-2017-9353 was discovered through a fuzzing initiative that aimed to identify potential security issues in Wireshark.
5
What component of Wireshark is impacted by CVE-2017-9353?
CVE-2017-9353 impacts the IPv6 dissector component of Wireshark.