Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2017-17085

Disclosure Date: December 01, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.
0
Attacker Value
Unknown

CVE-2017-17084

Disclosure Date: December 01, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length.
0
Attacker Value
Unknown

CVE-2017-17083

Disclosure Date: December 01, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.
0
Attacker Value
Unknown

CVE-2017-15193

Disclosure Date: October 10, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.
0
Attacker Value
Unknown

CVE-2017-15192

Disclosure Date: October 10, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.
0
Attacker Value
Unknown

CVE-2017-13766

Disclosure Date: August 30, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write. This was addressed in plugins/profinet/packet-dcerpc-pn-io.c by adding string validation.
0
Attacker Value
Unknown

CVE-2017-13767

Disclosure Date: August 30, 2017 (last updated November 08, 2023)
In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.
0
Attacker Value
Unknown

CVE-2017-11411

Disclosure Date: July 18, 2017 (last updated November 08, 2023)
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.
0
Attacker Value
Unknown

CVE-2017-11408

Disclosure Date: July 18, 2017 (last updated November 08, 2023)
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for successful list dissection.
0
Attacker Value
Unknown

CVE-2017-11410

Disclosure Date: July 18, 2017 (last updated November 08, 2023)
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding validation of the relationships between indexes and lengths. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-7702.
0