ID:1226 - Exploit for Null pointer dereference in Wireshark - CVE-2017-9347

 
Main Vulnerability Database Exploits ID:1226 - Exploit for Null pointer dereference in Wireshark - CVE-2017-9347

ID:1226 - Exploit for Null pointer dereference in Wireshark - CVE-2017-9347

Published: March 18, 2020


Vulnerability identifier: #VU6909
Vulnerability risk: Low
CVE-ID: CVE-2017-9347
CWE-ID: CWE-476
Exploitation vector: Remote access
Vulnerable software:
Wireshark

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to NULL pointer dereference in the ROS dissector when validating an OID. A remote attacker can inject a malformed packet epan/dissectors/asn1/ros/packet-ros-template.c onto the wire or persuade the target user to read a malformed packet trace file and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Update to version 2.2.7 or later.