Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15174

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

A flaw was found in Wireshark. A local attacker could exploit a crash in the Catapult DCT2000 protocol dissector. This vulnerability, requiring user interaction, leads to a denial of service, making the system unavailable.

Отчет

Moderate: A denial of service vulnerability exists in Wireshark due to a crash in the Catapult DCT2000 protocol dissector. This flaw requires local user interaction, as an attacker must provide a specially crafted capture file for a user to open. The impact is limited to the availability of the Wireshark application, making the system unavailable only in the context of network traffic analysis.

Меры по смягчению последствий

To reduce the risk, avoid opening untrusted network capture files that may contain malicious Catapult DCT2000 protocol data. Ensure that Wireshark is used only with data from trusted sources to prevent potential application crashes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2498289wireshark: Wireshark: Denial of Service via Catapult DCT2000 protocol dissector crash

EPSS

Процентиль: 1%
0.00092
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
nvd
около 1 месяца назад

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
debian
около 1 месяца назад

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 ...

CVSS3: 5.5
redos
5 дней назад

Уязвимость wireshark

CVSS3: 5.5
redos
5 дней назад

Уязвимость wireshark

EPSS

Процентиль: 1%
0.00092
Низкий

5.5 Medium

CVSS3