Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade wireshark-cli-debuginfoUpgrade wireshark-debugsourceUpgrade wireshark-develUpgrade wireshark-cli | Feb 17, 2025 | Aug 25, 2023 |
| Debian | — | Upgrade wireshark | Nov 27, 2023 | Aug 25, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2023 |
| Suse | — | Upgrade libwireshark15Upgrade wiresharkUpgrade wireshark-develUpgrade wireshark-ui-qtUpgrade libwsutil13Upgrade libwiretap12 | Sep 27, 2023 | Aug 25, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Aug 25, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 25, 2023 |
| Wireshark | — | Upgrade to Wireshark version 4.0.8Upgrade to Wireshark version 3.6.16 | Nov 17, 2023 | Aug 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub