Vulnerability CVE-2017-7701: Information

Description

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-bgp.c by using a different integer data type.

Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: April 13, 2017
Modified: Nov. 7, 2023
Error type identifier: CWE-835

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
wiresharksisyphus2.2.6-alt1.S14.2.4-alt1ALT-PU-2017-1470-1181725Fixed
wiresharkp102.2.6-alt1.S14.0.11-alt1ALT-PU-2017-1470-1181725Fixed
wiresharkp92.2.6-alt1.S14.0.8-alt1ALT-PU-2017-1470-1181725Fixed
wiresharkp82.2.6-alt1.M80P.13.0.6-alt1ALT-PU-2017-1472-1181726Fixed
wiresharkc10f12.2.6-alt1.S14.0.11-alt1ALT-PU-2017-1470-1181725Fixed
wiresharkc9f22.2.6-alt1.S14.0.11-alt1ALT-PU-2017-1470-1181725Fixed
wiresharkc72.2.7-alt1.M70C.12.2.7-alt1.M70C.1ALT-PU-2017-1698-1183820Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:wireshark:wireshark:2.0.0:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.4:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.9:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.2.2:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.1:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.11:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.7:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.2:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.8:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.3:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.2.5:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.6:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.10:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.2.3:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:2.0.5:*:*:*:*:*:*:*