Описание
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit an infinite loop vulnerability in the OpenFlow v6 protocol dissector by sending a specially crafted packet. This could lead to a denial of service (DoS), making the Wireshark application unresponsive.
Меры по смягчению последствий
To mitigate this issue, avoid opening untrusted capture files or analyzing network traffic from untrusted sources with Wireshark. If the OpenFlow v6 protocol dissection is not required, it can be disabled within Wireshark's preferences to prevent processing of these packets. This can be done by navigating to "Analyze" -> "Enabled Protocols" and unchecking "OpenFlow v6". Restarting Wireshark is required for the changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 7 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6 ...
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Уязвимость функции dissect_openflow_bundle_prop_v6() анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3