CVE-2017-11411: Wireshark

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.

Affected products

  • Wireshark Wireshark: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …

Published 2017-07-18. Last modified 2026-06-17.