CVE-2017-6014

Name
CVE-2017-6014
Description
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory http://www.debian.org/security/2017/dsa-3811
Third Party Advisory http://www.securityfocus.com/bid/96284
Issue Tracking https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13416
Third Party Advisory https://security.gentoo.org/glsa/201706-12

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* wireshark >= None <= 2.2.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status