CVE-2017-7748
UnknownEPSS 2.77%
Last modified
CVE-2017-7748 is a vulnerability of currently unknown severity. In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.. EPSS estimates a 2.77% chance of exploitation in the next 30 days.
Description
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wireshark | Wireshark | 2.0.0 |
| Wireshark | Wireshark | 2.0.1 |
| Wireshark | Wireshark | 2.0.2 |
| Wireshark | Wireshark | 2.0.3 |
| Wireshark | Wireshark | 2.0.4 |
| Wireshark | Wireshark | 2.0.5 |
| Wireshark | Wireshark | 2.0.6 |
| Wireshark | Wireshark | 2.0.7 |
| Wireshark | Wireshark | 2.0.8 |
| Wireshark | Wireshark | 2.0.9 |
| Wireshark | Wireshark | 2.0.10 |
| Wireshark | Wireshark | 2.0.11 |
| Wireshark | Wireshark | 2.2.0 |
| Wireshark | Wireshark | 2.2.1 |
| Wireshark | Wireshark | 2.2.2 |
| Wireshark | Wireshark | 2.2.3 |
| Wireshark | Wireshark | 2.2.4 |
| Wireshark | Wireshark | 2.2.5 |
References
- http://www.securityfocus.com/bid/97628Third Party Advisory, VDB Entry
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13581Issue Tracking, Patch
- https://www.wireshark.org/security/wnpa-sec-2017-21.htmlVendor Advisory
- http://www.securityfocus.com/bid/97628Third Party Advisory, VDB Entry
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=13581Issue Tracking, Patch
- https://www.wireshark.org/security/wnpa-sec-2017-21.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7748?
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.
How severe is CVE-2017-7748?
Severity scoring for CVE-2017-7748 is pending analysis. The EPSS model estimates a 2.77% probability of exploitation in the next 30 days.
How do I fix CVE-2017-7748?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7740Rejected reason: Not used
- CVE-2017-7741In libsndfile before 1.0.28, an error in the "flac_buffer_co…
- CVE-2017-7742In libsndfile before 1.0.28, an error in the "flac_buffer_co…
- CVE-2017-7745In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP…
- CVE-2017-7746In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK di…
- CVE-2017-7747In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketB…
- CVE-2017-7749A use-after-free vulnerability when using an incorrect URL d…
- CVE-2017-7750A use-after-free vulnerability during video control operatio…
- CVE-2017-7751A use-after-free vulnerability with content viewer listeners…
- CVE-2017-7752A use-after-free vulnerability during specific user interact…
- CVE-2017-7753An out-of-bounds read occurs when applying style rules to ps…
- CVE-2017-7754An out-of-bounds read in WebGL with a maliciously crafted "I…
Are you affected by CVE-2017-7748?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
