In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | Feb 20, 2018 | Dec 30, 2017 |
| Debian | — | Upgrade wireshark | Feb 20, 2019 | Dec 30, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade wiresharkUpgrade wireshark-gnome | Feb 13, 2018 | Dec 30, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade wireshark-gnomeUpgrade wireshark | Feb 13, 2018 | Dec 30, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 29, 2017 |
| Suse | — | Upgrade wireshark-gtkUpgrade libwsutil7Upgrade libwireshark9Upgrade libwscodecs1Upgrade libwiretap6Upgrade wiresharkUpgrade libwireshark8Upgrade wireshark-develUpgrade libwiretap7Upgrade libwsutil8 | Jan 16, 2018 | Dec 30, 2017 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Dec 30, 2017 |
| Wireshark | — | Upgrade to Wireshark version 2.2.12 | Jan 12, 2018 | Dec 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub