#VU33263 Infinite loop in Wireshark - CVE-2017-6014

 

#VU33263 Infinite loop in Wireshark - CVE-2017-6014

Published: February 17, 2017 / Updated: August 3, 2020


Vulnerability identifier: #VU33263
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-6014
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Wireshark
Software vendor:
Wireshark.org

Description

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory.


Remediation

Install update from vendor's website.

External links