Wireshark DOCSIS Dissector '/docsis/packet-docsis.c' Denial of Service Vulnerability
BID:101228
CVE-2017-15189 |Info
Wireshark DOCSIS Dissector '/docsis/packet-docsis.c' Denial of Service Vulnerability
| Bugtraq ID: | 101228 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2017-15189 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2017 12:00AM |
| Updated: | Oct 10 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Wireshark Wireshark 2.4.1 Wireshark Wireshark 2.4 |
| Not Vulnerable: |
Wireshark Wireshark 2.4.2 |
Discussion
Wireshark DOCSIS Dissector '/docsis/packet-docsis.c' Denial of Service Vulnerability
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
Attackers can exploit this issue to cause the application to enter an infinite loop consuming excessive CPU resources, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.1 are vulnerable.
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain types of packets.
Attackers can exploit this issue to cause the application to enter an infinite loop consuming excessive CPU resources, denying service to legitimate users.
Wireshark versions 2.4.0 through 2.4.1 are vulnerable.