CVE-2017-13765 describes a buffer over-read vulnerability in the IrCOMM dissector within Wireshark versions 2.4.0, 2.2.0-2.2.8, and 2.0.0-2.0.14, affecting Debian Linux distributions. This flaw, rated 7.5 HIGH on CVSS, allows an unauthenticated attacker to cause a denial of service (application crash) with low attack complexity. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability was addressed by adding length validation in the affected code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.0.14CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
>= 2.2.0, <= 2.2.8CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
2.4.0CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:2.4.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.