Описание
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. A NULL pointer dereference vulnerability exists within the CMS (Cryptographic Message Syntax) protocol dissector. This issue can be triggered by processing a specially crafted network capture file, leading to an application crash. A remote attacker could exploit this to cause a denial of service (DoS).
Отчет
A NULL pointer dereference was found in the CMS protocol dissector in Wireshark versions 4.4.0 through 4.4.18 and 4.6.0 through 4.6.7. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship an affected version of Wireshark.
Меры по смягчению последствий
Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
EPSS
4.7 Medium
CVSS3