Описание
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a specially crafted Universal Mobile Telecommunications System (UMTS) RRC protocol packet. The flaw resides in the UMTS RRC protocol dissector, which can lead to a crash of the Wireshark application. This can disrupt network analysis operations.
Отчет
This Moderate impact denial of service flaw in Wireshark's UMTS RRC protocol dissector can be triggered by processing a specially crafted packet. While exploitable by a remote attacker, successful exploitation requires a user to either open a malicious capture file or actively capture network traffic containing the crafted packet. This limits the attack surface to scenarios where Wireshark is actively used for network analysis.
Меры по смягчению последствий
To mitigate this issue, avoid opening untrusted capture files or analyzing untrusted live network traffic with Wireshark. Users should only process network data from trusted sources to prevent potential denial of service attacks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Affected | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
EPSS
5.5 Medium
CVSS3