Bugzilla – Bug 1148181
VUL-1: CVE-2017-6467: wireshark: Netscaler file parser infinite loop (wnpa-sec-2017-11)
Last modified: 2019-08-26 22:12:16 UTC
CVE-2017-6467 It was reported that Wireshark's Netscaler file parser could loop infinitely. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Upstream bug(s): https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12083 External References: https://www.wireshark.org/security/wnpa-sec-2017-11.html References: https://bugzilla.redhat.com/show_bug.cgi?id=1429589 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-6467 http://www.debian.org/security/2017/dsa-3811 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6467.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6467 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12083 https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=284ad58d288722a8725401967bff0c4455488f0c http://www.securityfocus.com/bid/96561 https://www.wireshark.org/security/wnpa-sec-2017-11.html
Fixed in all code streams.
on maintenance request