CVE-2017-11409

Description

In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.193

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Wireshark x64 2.0.14Windows
Vulnerability CVE-2017-11409 are affected in Wireshark (X64) 2.0.13Windows
Vulnerabilities CVE-2017-11406,CVE-2017-11407,CVE-2017-11408,CVE-2017-11409 are affected in WireShark For Mac 2.0.13Mac
Multiple vulnerabilities are fixed in Wireshark for Mac 2.0.14Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338541Wireshark (3.6.24)
PATCH-343288Wireshark (X64) (4.4.2)
PATCH-611905WireShark for Mac (Apple Silicon) (4.4.9)
PATCH-612949WireShark for Mac (4.6.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234