Wireshark sharkd
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*
- >= 4.6.0, <= 4.6.4
- >= 4.4.0, <= 4.4.14
A denial-of-service vulnerability has been identified in the Wireshark sharkd utility, specifically in versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14. The issue arises from a heap-buffer-overflow in the frames method, triggered by a cached filter bitmap from previously loaded capture files. This flaw allows for a crash in the sharkd process.
Exploitation of this vulnerability leads to a crash of the sharkd utility, causing a denial-of-service condition.
The vulnerability can be reproduced by loading a smaller pcap file into sharkd, applying a filter that matches some but not all frames, and then loading a second pcap file with a larger frame count that is filtered in a way to cause the out-of-bounds read, such as by matching frames that are further along in the capture.
Users are advised to upgrade to Wireshark versions 4.6.5, 4.4.15 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.