[Secure-testing-team] Bug#885831: wireshark: CVE-2017-17935: Denial of service in the File_read_line function in epan/wslua/wslua_file.c

Salvatore Bonaccorso carnil at debian.org
Sat Dec 30 08:57:57 UTC 2017


Source: wireshark
Version: 2.4.3-1
Severity: normal
Tags: patch security upstream
Forwarded: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14295

Hi,

the following vulnerability was published for wireshark.

CVE-2017-17935[0]:
| The File_read_line function in epan/wslua/wslua_file.c in Wireshark
| through 2.2.11 does not properly strip '\n' characters, which allows
| remote attackers to cause a denial of service (buffer underflow and
| application crash) via a crafted packet that triggers the attempted
| processing of an empty line.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-17935
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17935
[1] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14295

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Secure-testing-team mailing list