Описание
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. This heap-based buffer overflow vulnerability in the dissection engine could allow a remote attacker to cause a denial of service. Exploitation requires a user to process a specially crafted network packet, leading to a crash of the application.
Отчет
A flaw was found in the dissection engine in Wireshark versions 4.4.0 through 4.4.17 and 4.6.0 through 4.6.7. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship an affected version of Wireshark.
Меры по смягчению последствий
Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 t ...
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
EPSS
3.1 Low
CVSS3