CVE-2017-6471
- EPSS 0.7%
- Veröffentlicht 04.03.2017 03:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length.
CVE-2017-6472
- EPSS 0.7%
- Veröffentlicht 04.03.2017 03:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence va...
CVE-2017-6473
- EPSS 0.7%
- Veröffentlicht 04.03.2017 03:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiretap/k12.c by validating the relationships between lengths and offsets.
CVE-2017-6474
- EPSS 0.7%
- Veröffentlicht 04.03.2017 03:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes.
CVE-2017-6014
- EPSS 0.42%
- Veröffentlicht 17.02.2017 07:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attem...
CVE-2017-5596
- EPSS 0.56%
- Veröffentlicht 25.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid a...
CVE-2017-5597
- EPSS 0.48%
- Veröffentlicht 25.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dhcpv6.c by changing a data type to avoid an inte...
CVE-2016-9376
- EPSS 1.48%
- Veröffentlicht 17.11.2016 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain length valu...
CVE-2016-9375
- EPSS 1.48%
- Veröffentlicht 17.11.2016 05:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.
CVE-2016-9374
- EPSS 1.22%
- Veröffentlicht 17.11.2016 05:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable prope...