Описание
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the C12.22 protocol dissector, which is responsible for interpreting network traffic. By sending a specially crafted network packet, an attacker could cause the Wireshark application to crash, leading to a denial of service (DoS). This prevents the legitimate use of the network analysis tool.
Отчет
This is an Important denial of service vulnerability in Wireshark's C12.22 protocol dissector. A remote attacker can trigger a crash by sending a specially crafted network packet, disrupting network analysis operations. This impact is significant for systems where Wireshark is actively deployed for network traffic inspection, as it can prevent legitimate use of the tool without requiring user interaction or elevated privileges.
Меры по смягчению последствий
To reduce the risk of exploitation, avoid analyzing untrusted network capture files with Wireshark. It is also recommended to run Wireshark within a sandboxed environment to limit the potential impact of a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Under investigation | ||
| Red Hat Enterprise Linux 6 | wireshark | Under investigation | ||
| Red Hat Enterprise Linux 7 | wireshark | Under investigation | ||
| Red Hat Enterprise Linux 8 | wireshark | Under investigation | ||
| Red Hat Enterprise Linux 9 | wireshark | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Уязвимость функции decrypt_packet() анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3