Описание
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. This vulnerability, located in the 3gpp phone log file parser, could allow a local attacker to trigger a crash by enticing a user to open a specially crafted log file. This could lead to a Denial of Service (DoS).
Отчет
This Moderate impact vulnerability in Wireshark's 3gpp phone log file parser requires a local attacker to trick a user into opening a specially crafted log file. Successful exploitation could lead to a denial of service, affecting the availability of the Wireshark application.
Меры по смягчению последствий
To mitigate this issue, users should avoid opening 3gpp phone log files from untrusted or suspicious sources with Wireshark. Exercise caution when handling files from unknown origins to prevent potential denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Уязвимость механизма обработки журнала телефонных звонков 3gpp анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.7 Medium
CVSS3