← Back

CVE-2017-13766

nvd nist
Published: Aug 30, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write. This was addressed in plugins/profinet/packet-dcerpc-pn-io.c by adding string validation.

Affected (23)

Products: Wireshark: Wireshark
1 product
Wireshark
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Wireshark
Version 2.0.0
Version 2.0.10
Version 2.0.11
Version 2.0.12
Version 2.0.13
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Wireshark
Version 2.2.0
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.4.0

Timeline

No history available yet.