Debian Security Advisory

DLA-826-1 wireshark -- LTS security update

Date Reported:
17 Feb 2017
Affected Packages:
wireshark
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 855408.
In Mitre's CVE dictionary: CVE-2017-6014.
More information:

It was discovered that there was denial of service vulnerability in wireshark, a network traffic analyzer.

A malformed NATO Ground Moving Target Indicator Format ("STANAG 4607") capture file could cause a memory exhausion/infinite loop.

For Debian 7 Wheezy, this issue has been fixed in wireshark version 1.12.1+g01b65bf-4+deb8u6~deb7u6.

We recommend that you upgrade your wireshark packages.