Wireshark 'epan/wslua/wslua_file.c 'Denial of Service Vulnerability (CVE-2017-17935)
Wireshark 'epan/wslua/wslua_file.c 'Denial of Service Vulnerability (CVE-2017-17935)
Release date:
Updated on:
Affected Systems:
Wireshark <= 2.2.11
Description:
Bugtraq id: 102311
CVE (CAN) ID: CVE-2017-17935
Wireshark is the most popular network protocol parser.
In Wireshark 2.2.11 and earlier versions, the epan/wslua/wslua_file.c/File_read_line function does not correctly Delete the '\ n' character, which allows remote attackers to construct packets, cause a denial of service (buffer overflow and application crash ).
<* Source: Young
*>
Suggestion:
Vendor patch:
Wireshark
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.wireshark.org/
Https://bugs.wireshark.org/bugzilla/show_bug.cgi? Id = 14295
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1529592
Https://access.redhat.com/security/cve/cve-2017-17935
Install the network traffic analysis tool Wireshark in Ubuntu 16.04
Install Wireshark 2.4.3 through PPA in Ubuntu 17.10