In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | Feb 20, 2018 | Dec 30, 2017 |
| Debian | — | Upgrade wireshark | Feb 20, 2019 | Dec 30, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade wiresharkUpgrade wireshark-gnome | Feb 13, 2018 | Dec 30, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade wireshark-gnomeUpgrade wireshark | Feb 13, 2018 | Dec 30, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 29, 2017 |
| Suse | — | Upgrade libwireshark9Upgrade libwiretap6Upgrade wiresharkUpgrade libwscodecs1Upgrade libwsutil7Upgrade libwireshark8Upgrade wireshark-gtkUpgrade wireshark-develUpgrade libwsutil8Upgrade libwiretap7 | Jan 16, 2018 | Dec 30, 2017 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Dec 30, 2017 |
| Wireshark | — | Upgrade to Wireshark version 2.2.12 | Jan 12, 2018 | Dec 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub