CVE-2017-6014 describes an infinite loop and memory exhaustion vulnerability in Wireshark versions 2.2.4 and earlier. A specially crafted or malformed STANAG 4607 capture file can trigger this flaw, causing the application to continuously attempt to read a zero-length packet due to a null packet size field, leading to rapid system memory exhaustion. This vulnerability is rated 7.5 HIGH, indicating a severe impact. It is remotely exploitable with low attack complexity, requiring no user interaction or privileges, and its primary impact is denial of service (availability). There is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.4CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.