← Back

CVE-2017-11411

nvd nist
Published: Jul 18, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.

Affected (22)

Products: Wireshark: Wireshark
1 product
Wireshark
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Wireshark
Version 2.0.0
Version 2.0.10
Version 2.0.11
Version 2.0.12
Version 2.0.13
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Wireshark
Version 2.2.0
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7

References (6)

Timeline

No history available yet.