Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade wireshark-cliUpgrade wiresharkUpgrade wireshark-develUpgrade wireshark-debuginfo | Jul 21, 2023 | Jun 7, 2023 |
| Amazon_linux | — | Upgrade wireshark | Jul 20, 2023 | Jun 7, 2023 |
| Amazon_linux_2023 | — | Upgrade wireshark-debugsourceUpgrade wireshark-cliUpgrade wireshark-develUpgrade wireshark-cli-debuginfo | Mar 10, 2025 | Jun 7, 2023 |
| Debian | — | Upgrade wireshark | Oct 19, 2023 | Jun 7, 2023 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Sep 18, 2023 | Jun 7, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 7, 2023 |
| Suse | — | Upgrade libwiretap12Upgrade libwsutil13Upgrade wireshark-develUpgrade libwireshark15Upgrade wiresharkUpgrade wireshark-ui-qt | Aug 10, 2023 | Jun 7, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 7, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 7, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub