Improper input validation in Wireshark - CVE-2017-17083
Published: December 11, 2017 / Updated: December 12, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the NetBIOS dissector in epan/dissectors/packet-netbios.c when processing network packets. A remote attacker can send a specially crafted packet and crash the vulnerable application.
Affected software
Debian Linux
Fedora
wireshark (Alpine package)
firefox-esr (Alpine package)
wireshark
How to mitigate CVE-2017-17083
wireshark - update to 2.4.3-1.fc27