A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 21, 2024 |
| Suse | — | Upgrade wireshark-gtkUpgrade wiresharkUpgrade libwireshark9Upgrade wireshark-ui-qtUpgrade libwsutil15Upgrade libwireshark18Upgrade libwscodecs1Upgrade libwiretap15Upgrade libwsutil8Upgrade libwsutil13Upgrade libwiretap12Upgrade libwsutil16Upgrade libwiretap7Upgrade libwireshark17Upgrade libwireshark15Upgrade libwiretap14Upgrade wireshark-devel | Apr 22, 2024 | Feb 21, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub