A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 21, 2024 |
| Suse | — | Upgrade libwiretap15Upgrade libwscodecs1Upgrade libwireshark9Upgrade wireshark-gtkUpgrade wireshark-ui-qtUpgrade wiresharkUpgrade libwsutil8Upgrade libwsutil15Upgrade libwireshark18Upgrade libwiretap12Upgrade libwsutil16Upgrade libwireshark15Upgrade libwiretap7Upgrade libwsutil13Upgrade wireshark-develUpgrade libwireshark17Upgrade libwiretap14 | Apr 22, 2024 | Feb 21, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub