Описание
Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file
A flaw was found in the EAP dissector of Wireshark. This issue occurs when decoding malformed packets from a pcap file or from the network, causing an use-after-free problem, resulting in a Denial of Service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
Red Hat Enterprise Linux 7 | wireshark | Out of support scope | ||
Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file
Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file
Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial o ...
Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file
EPSS
6.5 Medium
CVSS3