Bugzilla – Bug 1042324
VUL-1: wireshark: various dissector crashes and infinite loops fixed in Wireshark 2.2.7/2.0.13
Last modified: 2017-06-02 09:20:33 UTC
Fixed in 2.2.7: https://www.wireshark.org/docs/relnotes/wireshark-2.2.7.html https://www.wireshark.org/lists/wireshark-announce/201706/msg00000.html * CVE-2017-9352: Bazaar dissector infinite loop (wnpa-sec-2017-22) * CVE-2017-9348: DOF dissector read overflow (wnpa-sec-2017-23) * CVE-2017-9351: DHCP dissector read overflow (wnpa-sec-2017-24) * CVE-2017-9346: SoulSeek dissector infinite loop (wnpa-sec-2017-25) * CVE-2017-9345: DNS dissector infinite loop (wnpa-sec-2017-26) * CVE-2017-9349: DICOM dissector infinite loop (wnpa-sec-2017-27) * CVE-2017-9350: openSAFETY dissector memory exhaustion (wnpa-sec-2017-28) * CVE-2017-9344: BT L2CAP dissector divide by zero (wnpa-sec-2017-29) * CVE-2017-9343: MSNIP dissector crash (wnpa-sec-2017-30) * CVE-2017-9347: ROS dissector crash (wnpa-sec-2017-31) * CVE-2017-9354: RGMP dissector crash (wnpa-sec-2017-32) * CVE-2017-9353: IPv6 dissector crash (wnpa-sec-2017-33) Fixed in 2.0.13: https://www.wireshark.org/docs/relnotes/wireshark-2.0.13.html https://www.wireshark.org/lists/wireshark-announce/201706/msg00001.html * CVE-2017-9352: Bazaar dissector infinite loop (wnpa-sec-2017-22) * CVE-2017-9351: DHCP dissector read overflow (wnpa-sec-2017-24) * CVE-2017-9346: SoulSeek dissector infinite loop (wnpa-sec-2017-25) * CVE-2017-9345: DNS dissector infinite loop (wnpa-sec-2017-26) * CVE-2017-9349: DICOM dissector infinite loop (wnpa-sec-2017-27) * CVE-2017-9350: openSAFETY dissector memory exhaustion (wnpa-sec-2017-28) * CVE-2017-9344: BT L2CAP dissector divide by zero (wnpa-sec-2017-29) * CVE-2017-9343: MSNIP dissector crash (wnpa-sec-2017-30) * CVE-2017-9354: RGMP dissector crash (wnpa-sec-2017-32)