The vendor explicitly identifies these products as affected by this CVE.
- wireshark as a component of Red Hat Enterprise Linux 10
- wireshark-cli as a component of Red Hat Enterprise Linux 10
- wireshark-devel as a component of Red Hat Enterprise Linux 10
- wireshark.src as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in Wireshark. This vulnerability, a buffer over-read, occurs when the Tektronix K12xx file parser processes a specially crafted file. A remote attacker could exploit this by convincing a user to open a malicious Tektronix K12xx file, leading to a crash of the Wireshark application and resulting in a denial of service.
- Remediation
- Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
