epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Nov 26, 2010 |
| Suse | — | Upgrade libwiretap6Upgrade libwiretap15Upgrade libwsutil7Upgrade wiresharkUpgrade libwscodecs1Upgrade wireshark-develUpgrade wireshark-gtkUpgrade libwsutil8Upgrade libwireshark9Upgrade libwiretap7Upgrade libwireshark8Upgrade libwsutil16Upgrade wireshark-ui-qtUpgrade libwireshark18 | Feb 17, 2015 | Jun 28, 2013 |
| Wireshark | — | Upgrade to Wireshark version 1.4.2 | Oct 4, 2017 | Nov 26, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub