CVE-2017-6470

Name
CVE-2017-6470
Description
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory http://www.debian.org/security/2017/dsa-3811
Third Party Advisory http://www.securityfocus.com/bid/96563
Issue Tracking https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13432
cve@mitre.org https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=0b89174ef4c531a1917437fff586fe525ee7bf2d
Vendor Advisory https://www.wireshark.org/security/wnpa-sec-2017-10.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* wireshark >= 2.0.0 <= 2.0.10
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* wireshark >= 2.2.0 <= 2.2.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wireshark edge-community 2.2.5-r0 None fixed
wireshark edge-community 2.2.4-r1 None possibly vulnerable
wireshark edge-community 2.0.5-r0 None possibly vulnerable
wireshark 3.22-community 2.2.5-r0 None fixed
wireshark 3.21-community 2.2.5-r0 None fixed
wireshark 3.20-community 2.2.5-r0 None fixed
wireshark 3.19-community 2.2.5-r0 None fixed
wireshark 3.18-community 2.2.5-r0 None fixed
wireshark 3.17-community 2.2.5-r0 None fixed