Описание
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit a denial of service vulnerability in the ESS protocol dissector by processing a specially crafted network packet. This could lead to the application crashing, preventing network traffic analysis. The impact is limited to the availability of the Wireshark application itself.
Отчет
This Moderate impact denial of service vulnerability affects Wireshark's ESS protocol dissector. An attacker can crash the application by providing a specially crafted network packet for analysis. The impact is limited to the availability of the Wireshark application, requiring user interaction to process the malicious input.
Меры по смягчению последствий
To mitigate this issue prior to patching, disable the ESS protocol dissector by running tshark --disable-protocol ess or unchecking ESS under Analyze > Enabled Protocols. Additionally, avoid opening packet capture files from untrusted sources and restrict live capture to trusted networks using host firewalls. On systems where packet analysis is non-essential, remove the wireshark package entirely or restrict execution permissions strictly to authorized administrators.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Affected | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Уязвимость анализатора протокола ESS анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3