7.8
CVSSv2

CVE-2017-15193

Published: 10/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 2.2.6

wireshark wireshark 2.2.0

wireshark wireshark 2.4.0

wireshark wireshark 2.2.2

wireshark wireshark 2.2.1

wireshark wireshark 2.2.4

wireshark wireshark 2.2.5

wireshark wireshark 2.2.7

wireshark wireshark 2.2.8

wireshark wireshark 2.2.3

wireshark wireshark 2.2.9

wireshark wireshark 2.4.1

Vendor Advisories

In Wireshark 240 to 241 and 220 to 229, the MBIM dissector could crash or exhaust system memory This was addressed in epan/dissectors/packet-mbimc by changing the memory-allocation approach ...
A flaw has been discovered in wireshark before 242 in the MBIM dissector when pre sizing wmem arrays leading to resource consumption and application crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file ...