The vendor explicitly identifies these products as affected by this CVE.
- wireshark as a component of Red Hat Enterprise Linux 10
- wireshark-cli as a component of Red Hat Enterprise Linux 10
- wireshark-devel as a component of Red Hat Enterprise Linux 10
- wireshark.src as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in Wireshark. This heap-based buffer overflow vulnerability in the dissection engine could allow a remote attacker to cause a denial of service. Exploitation requires a user to process a specially crafted network packet, leading to a crash of the application.
- Remediation
- Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
