Описание
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark's SSH (Secure Shell) protocol dissector. A remote attacker could craft a malicious network capture file that, when opened by a user, would cause the Wireshark application to crash. This vulnerability leads to a denial of service, preventing the user from analyzing network traffic.
Отчет
Moderate: A denial of service flaw exists in Wireshark's SSH protocol dissector, where processing a specially crafted network capture file can lead to application termination. This issue requires user interaction to open a malicious file, limiting its impact to the availability of the Wireshark application for network traffic analysis.
Меры по смягчению последствий
Users should avoid opening untrusted or suspicious network capture files with Wireshark. Running Wireshark in a sandboxed environment can further limit the impact of potential crashes. No direct configuration options are available to prevent this flaw without affecting Wireshark's core functionality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to ...
EPSS
5.5 Medium
CVSS3