Описание
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. The Bluetooth Attribute Protocol dissector contains an out-of-bounds read vulnerability. A remote attacker could exploit this by crafting a malicious Bluetooth packet, leading to a crash of the Wireshark application. This crash results in a denial of service (DoS), preventing the user from analyzing network traffic.
Отчет
A flaw was found in the Bluetooth Attribute Protocol dissector in Wireshark versions 4.4.0 through 4.4.17 and 4.6.0 through 4.6.7. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship an affected version of Wireshark.
Меры по смягчению последствий
Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4 ...
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
EPSS
4.7 Medium
CVSS3