Описание
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service by crafting a malicious TLS Encrypted Client Hello (ECH) packet. When Wireshark attempts to decrypt this malformed packet, it can lead to a crash of the application, making it unavailable.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2498279wireshark: Wireshark: Denial of Service via TLS ECH decryptor crash
6.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
ubuntu
около 1 месяца назад
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
CVSS3: 5.5
nvd
около 1 месяца назад
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
CVSS3: 5.5
debian
около 1 месяца назад
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of s ...
6.5 Medium
CVSS3