Описание
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the pcapng file parser, leading to a crash of the application. This denial of service (DoS) could prevent legitimate users from accessing the service, impacting its availability.
Отчет
This Moderate impact denial of service flaw in Wireshark's pcapng file parser can be triggered when processing a specially crafted capture file. An attacker could provide a malicious pcapng file, leading to an application crash and preventing legitimate network analysis. Exploitation requires user interaction, as the user must open the malicious file.
Меры по смягчению последствий
To mitigate this issue, users should avoid opening pcapng files from untrusted or unknown sources. Exercise caution when handling network capture files, especially those received unexpectedly or from external origins.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
Связанные уязвимости
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of ...
EPSS