Bugzilla – Bug 1148189
VUL-0: CVE-2017-6473: wireshark: K12 file parser crash (wnpa-sec-2017-09)
Last modified: 2020-08-13 11:52:09 UTC
CVE-2017-6473 It was reported that Wireshark's K12 file parser could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Upstream bug(s): https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13431 External References: https://www.wireshark.org/security/wnpa-sec-2017-09.html References: https://bugzilla.redhat.com/show_bug.cgi?id=1429586 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-6473 http://www.debian.org/security/2017/dsa-3811 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6473.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6473 https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13431 https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=7edc761a01cda8e1b37677f673985582330317d2 http://www.securityfocus.com/bid/96565 https://www.wireshark.org/security/wnpa-sec-2017-09.html
This issue was fixed in all code streams but never mentioned in the .changes file. See also the tracking bug for a number of adjacent CVEs: https://bugzilla.suse.com/show_bug.cgi?id=1027998
fixed