7.5
CVSSv3

CVE-2017-6470

Published: 04/03/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #855408 wireshark: CVE-2017-6014: crafted or malformed STANAG 4607 capture file will cause an infinite loop Package: src:wireshark; Maintainer for src:wireshark is Balint Reczey <rbalint@ubuntucom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 17 Feb 2017 15:42:01 UTC Sev ...
It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for ASTERIX, DHCPv6, NetScaler, LDSS, IAX2, WSP, K12 and STANAG 4607, that could lead to various crashes, denial-of-service or execution of arbitrary code For the stable distribution (jessie), these problems have been fixed in version ...
In Wireshark 220 to 224 and 200 to 2010, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file This was addressed in epan/dissectors/packet-iax2c by constraining packet lateness ...