Record summary

CVE-2017-17085 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWireshark 2.4.0 < 2.4.2 / 2.2.0 < 2.2.10 - CIP Safety Dissector CrashExploitDB exploitby WiresharkNot analyzed1 file
ExploitDB

PoC details

References

9