Описание
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit this vulnerability by crafting a malicious USB Human Interface Device (HID) protocol packet. This could lead to an infinite loop in the dissector, causing a denial of service (DoS) condition, making the application unresponsive.
Меры по смягчению последствий
To mitigate this issue, avoid opening untrusted capture files or analyzing network traffic from untrusted sources with Wireshark. If processing untrusted data is unavoidable, consider running Wireshark within a sandboxed environment to limit potential impact.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 7 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 a ...
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Уязвимость диссектора протокола USB HID анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызывать отказ в обслуживании
EPSS
5.5 Medium
CVSS3