Описание
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. A local attacker could exploit a crash in the Bluetooth BR/EDR FHS protocol dissector, requiring user interaction. This vulnerability could lead to a denial of service, making the application unavailable to users.
Отчет
This Moderate impact flaw in Wireshark is due to a Bluetooth BR/EDR FHS protocol dissector crash. Exploitation requires user interaction, as an attacker must convince a local user to open a specially crafted capture file, leading to a denial of service for the application.
Меры по смягчению последствий
To mitigate this issue, users should avoid opening untrusted or suspicious capture files with Wireshark. If Wireshark is not essential for system operation, consider removing the package to eliminate the attack surface. Removing Wireshark may also remove other desktop environment packages if they depend on it, potentially impacting graphical functionality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | ||
| Red Hat Enterprise Linux 6 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 7 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Not affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Not affected |
Показывать по
Дополнительная информация
Статус:
5.5 Medium
CVSS3
Связанные уязвимости
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4. ...
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
5.5 Medium
CVSS3