Описание
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. A heap-based buffer overflow vulnerability exists within the Bluetooth Audio/Video Remote Control Profile (AVRCP) protocol dissector. This flaw can be triggered by a local user processing a specially crafted Bluetooth AVRCP packet, which requires user interaction. Successful exploitation leads to a crash of the Wireshark application, resulting in a denial of service.
Отчет
A heap-based buffer overflow was found in the Bluetooth AVRCP dissector in Wireshark versions 4.4.0 through 4.4.17 and 4.6.0 through 4.6.7. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship an affected version of Wireshark.
Меры по смягчению последствий
Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and ...
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
EPSS
5.5 Medium
CVSS3