First published: Wed Jun 21 2017(Updated: )
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =2.2.7 | |
Debian GNU/Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9766 has a severity rating that indicates a potential denial of service due to stack exhaustion in Wireshark.
To fix CVE-2017-9766, update Wireshark to the latest version that addresses the vulnerability, specifically beyond version 2.2.7.
The impact of CVE-2017-9766 on affected systems includes the possibility of remote denial of service attacks that can cause application crashes.
CVE-2017-9766 specifically affects Wireshark version 2.2.7.
Yes, CVE-2017-9766 can be exploited remotely, allowing attackers to affect system stability.