CVE-2017-9354: Input Validation
Published Jun 2, 2017
·Updated
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an IPv4 address.
Affected Software
2 affected components
Wireshark Wireshark>=2.0.0<=2.0.12
Wireshark Wireshark>=2.2.0<=2.2.6
Remediation
Patch Available
Event History
Jun 2, 2017
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9354?
CVE-2017-9354 is categorized as a moderate severity vulnerability that can lead to application crashes.
2
How do I fix CVE-2017-9354?
To fix CVE-2017-9354, upgrade to Wireshark version 2.2.7 or 2.0.13 or later.
3
What are the affected versions of Wireshark for CVE-2017-9354?
Wireshark versions 2.0.0 through 2.0.12 and 2.2.0 through 2.2.6 are affected by CVE-2017-9354.
4
What type of attack does CVE-2017-9354 enable?
CVE-2017-9354 can enable denial of service attacks due to application crashes caused by the RGMP dissector.
5
What component of Wireshark does CVE-2017-9354 affect?
CVE-2017-9354 specifically affects the RGMP dissector in Wireshark.