Описание
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark. A local attacker could exploit a crash in the Catapult DCT2000 protocol dissector. This vulnerability, requiring user interaction, leads to a denial of service, making the system unavailable.
Отчет
Moderate: A denial of service vulnerability exists in Wireshark due to a crash in the Catapult DCT2000 protocol dissector. This flaw requires local user interaction, as an attacker must provide a specially crafted capture file for a user to open. The impact is limited to the availability of the Wireshark application, making the system unavailable only in the context of network traffic analysis.
Меры по смягчению последствий
To reduce the risk, avoid opening untrusted network capture files that may contain malicious Catapult DCT2000 protocol data. Ensure that Wireshark is used only with data from trusted sources to prevent potential application crashes.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 ...
EPSS
5.5 Medium
CVSS3