Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0961

Опубликовано: 14 янв. 2026
Источник: redhat
CVSS3: 5.5

Описание

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

A flaw was found in Wireshark. This vulnerability allows an attacker to trigger a crash in the BLF file parser by providing a specially crafted file. Successful exploitation leads to a denial of service (DoS), making the application unavailable to legitimate users.

Отчет

This vulnerability is rated Moderate for Red Hat. An out-of-bounds write flaw in the Wireshark BLF file parser can lead to a denial of service. This issue requires user interaction, as an attacker would need to trick a user into opening a specially crafted BLF file.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening or processing untrusted BLF (Binary Logging Format) files with Wireshark. Exercise caution when handling BLF files from unknown or unverified sources to prevent potential denial of service attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkFix deferred
Red Hat Enterprise Linux 7wiresharkFix deferred
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2429763Wireshark: Wireshark: Denial of Service vulnerability in BLF file parser

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS3: 5.5
nvd
3 месяца назад

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS3: 5.5
debian
3 месяца назад

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 ...

CVSS3: 5.5
github
3 месяца назад

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость анализатора трафика компьютерных сетей Wireshark, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

5.5 Medium

CVSS3