Описание
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark. A local user could exploit this vulnerability by processing a specially crafted FMP/NOTIFY protocol packet. This could lead to a denial of service (DoS) due to a crash in the protocol dissector, making the application unavailable.
Отчет
This Moderate impact flaw in Wireshark allows a local attacker to cause a denial of service by processing a specially crafted FMP/NOTIFY protocol packet. The vulnerability requires user interaction, as an attacker must trick a local user into opening a malicious packet capture file, limiting the attack surface.
Меры по смягчению последствий
To mitigate this issue, users should avoid opening untrusted or suspicious packet capture files with Wireshark. Restricting access to systems running Wireshark and ensuring that only trusted network captures are analyzed can further reduce the risk of exploitation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4. ...
EPSS
5.5 Medium
CVSS3