Security Advisory

CVE-2017-11410

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-07-18 21:00:00
Last updated 2024-08-05 18:05:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding validation of the relationships between indexes and lengths. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-7702.