Wireshark
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*
- >= 4.4.0, <= 4.4.8
A denial-of-service vulnerability has been identified in the Wireshark SSH dissector, present in versions 4.4.0 through 4.4.8. This issue allows Wireshark to crash when it processes a malformed packet, either injected onto the network or contained within a packet trace file.
Exploitation of this vulnerability leads to a crash of the Wireshark application.
The vulnerability can be reproduced by using Wireshark to open a malformed packet trace file that contains SSH data. Alternatively, injecting a malformed SSH packet onto the network can also trigger the crash.
Users are advised to upgrade to Wireshark version 4.4.9 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.