The vendor explicitly identifies these products as affected by this CVE.
- wireshark as a component of Red Hat Enterprise Linux 10
- wireshark-cli as a component of Red Hat Enterprise Linux 10
- wireshark-devel as a component of Red Hat Enterprise Linux 10
- wireshark.src as a component of Red Hat Enterprise Linux 10
- wireshark as a component of Red Hat Enterprise Linux 6
- wireshark-devel as a component of Red Hat Enterprise Linux 6
- wireshark-gnome as a component of Red Hat Enterprise Linux 6
- wireshark.src as a component of Red Hat Enterprise Linux 6
- wireshark as a component of Red Hat Enterprise Linux 7
- wireshark-devel as a component of Red Hat Enterprise Linux 7
- wireshark-gnome as a component of Red Hat Enterprise Linux 7
- wireshark.src as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in Wireshark. An unauthenticated remote attacker could exploit a vulnerability in the C12.22 protocol dissector by sending specially crafted network traffic. This could lead to a crash of the application, resulting in a Denial of Service (DoS).
- Remediation
- Do not populate the C12.22 decryption table, and disable the c1222.decrypt preference if crypto verification is not required. Avoid opening untrusted capture files or capturing C12.22 (TCP/1153) traffic from untrusted networks. If the C12.22 dissector is unused, disable it in protocol preferences.
