Описание
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| wireshark | fixed | 4.0.10-1 | package | |
| wireshark | not-affected | bullseye | package | |
| wireshark | not-affected | buster | package |
Примечания
https://gitlab.com/wireshark/wireshark/-/issues/19322
https://www.wireshark.org/security/wnpa-sec-2023-27.html
Introduced by: https://gitlab.com/wireshark/wireshark/-/commit/b46d244a9ba55daaed1ebbb15f5ea56231658d3d (v3.5.0)
Связанные уязвимости
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
Memory Allocation with Excessive Size Value in Wireshark