Wireshark
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*
- >= 4.6.0, <= 4.6.4
- >= 4.4.0, <= 4.4.14
A denial-of-service vulnerability has been identified in Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The issue arises from a double-free error in the iLBC audio codec, where the codec's release function improperly frees memory that has already been released, leading to a crash when Wireshark is closed. This vulnerability can be triggered by playing an iLBC RTP stream and then closing the application.
Exploitation of this vulnerability causes Wireshark to crash.
The vulnerability can be reproduced by loading a packet capture file containing a malformed iLBC RTP stream into Wireshark. After playing the stream through the Telephony -> VoIP Calls menu, closing Wireshark will result in a crash.
Users are advised to upgrade to Wireshark versions 4.6.5, 4.4.15 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.