Описание
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the H.245 protocol dissector. By crafting and sending malformed H.245 protocol data, an attacker could cause the Wireshark application to crash when a user processes this untrusted network data, leading to a denial of service.
Отчет
This localized Denial of Service vulnerability is rated Moderate because it solely causes application instability, leaving the underlying system and data secure. Furthermore, the exploit cannot trigger autonomously; it strictly requires a user to actively process crafted live network traffic or open a malicious capture file.
Меры по смягчению последствий
To mitigate this issue, disable the H.245 protocol dissector by running tshark --disable-protocol h245 or unchecking H.245 under Analyze > Enabled Protocols. Additionally, avoid opening packet capture files from untrusted sources and restrict live capture to trusted networks using host firewalls. On systems where packet analysis is non-essential, remove the wireshark package entirely or restrict execution permissions strictly to authorized administrators.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Affected | ||
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wireshark | Affected | ||
| Red Hat Enterprise Linux 8 | wireshark | Affected | ||
| Red Hat Enterprise Linux 9 | wireshark | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 a ...
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Уязвимость анализатора протокола H.245 анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3