Описание
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
A flaw was found in the TTX Logger file parser in Wireshark. This issue occurs when malformed packets are decoded from a packet capture file, causing a heap-based buffer overflow, resulting in a denial of service.
Отчет
This issue will cause a crash in Wireshark, with no evidence of arbitrary code execution. This vulnerability can only be exploited when a malformed packet capture file is processed. Due to these reasons, this flaw has been rated with a moderate severity.
Меры по смягчению последствий
To mitigate this vulnerability, do not open untrusted capture files.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.6 Medium
CVSS3
Связанные уязвимости
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of servic ...
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
EPSS
6.6 Medium
CVSS3