Описание
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. An unauthenticated remote attacker could exploit a vulnerability in the C12.22 protocol dissector by sending specially crafted network traffic. This could lead to a crash of the application, resulting in a Denial of Service (DoS).
Отчет
This Moderate impact denial of service vulnerability in Wireshark's C12.22 protocol dissector could be triggered by processing a specially crafted capture file or analyzing malicious network traffic. Exploitation requires user interaction, such as opening a malicious file, limiting its impact in typical Red Hat deployments where Wireshark is used for network analysis rather than as a continuously exposed service.
Меры по смягчению последствий
Do not populate the C12.22 decryption table, and disable the c1222.decrypt preference if crypto verification is not required. Avoid opening untrusted capture files or capturing C12.22 (TCP/1153) traffic from untrusted networks. If the C12.22 dissector is unused, disable it in protocol preferences.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Affected | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Уязвимость функции Eax_Decrypt() анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3