Improper input validation in Wireshark - CVE-2017-11408
Published: December 9, 2017 / Updated: December 12, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the AMQP dissector in epan/dissectors/packet-amqp.c when processing network packets. A remote attacker can send a specially crafted packet and crash the vulnerable application.
Affected software
Debian Linux
Arch Linux
Fedora
wireshark (Alpine package)
wireshark
How to mitigate CVE-2017-11408
wireshark - update to 2.2.8-1.fc26