CVE-2017-7746: Debian Linux
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.
Affected products
- Debian Debian Linux: version 8.0 only
- Wireshark Wireshark: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …
Published 2017-04-12. Last modified 2026-06-17.