CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-9616 Wireshark Multiple Stack Exhaustion Vulnerabilities

2017年6月27日 1086点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

Wireshark is a network protocol analyzer available for multiple operating systems. It lets you capture and interactively browse the traffic running on a computer network.

Multiple vulnerabilities were reported in Wireshark. A remote user can cause denial of service conditions on the target system.
Overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function. (CVE-2017-9616)
Deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_tag function.(CVE-2017-9617)

Affected Versions:
Wireshark 2.2.7

QID Detection Logic (authenticated):
The QID checks for vulnerable version of "wireshark.exe". The location of the file is determined by the registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wireshark" value "UninstallString".

漏洞危害

Successful exploitation of the vulnerability will cause disruption of Service.

解决方案

Currently there is no fix released by the vendor.

0daybank

标签: 暂无
最后更新:2017年6月27日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me