CVE-2017-17935: Debian Linux

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that triggers the attempted processing of an empty line.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Wireshark Wireshark: up to and including 2.2.11

Published 2017-12-27. Last modified 2026-06-17.