Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15170

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

A flaw was found in Wireshark's Z39.50 protocol dissector. A heap buffer overflow can occur when the dissector processes malformed Z39.50 records with partial directory entries, as the pre-allocated array size is calculated using floor division and does not account for additional partial entries. An attacker could exploit this by convincing a user to open a specially crafted packet capture file, causing Wireshark to crash. This results in a denial of service.

Отчет

Moderate: A heap buffer overflow in Wireshark's Z39.50 protocol dissector can lead to a denial of service. This flaw requires user interaction, specifically opening a specially crafted packet capture file, limiting its immediate impact on typical server deployments.

Меры по смягчению последствий

Avoid opening capture files from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2498313wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash

EPSS

Процентиль: 5%
0.00157
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
nvd
около 1 месяца назад

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
debian
около 1 месяца назад

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 ...

CVSS3: 5.5
redos
6 дней назад

Уязвимость wireshark

CVSS3: 5.5
redos
6 дней назад

Уязвимость wireshark

EPSS

Процентиль: 5%
0.00157
Низкий

5.5 Medium

CVSS3