A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 21, 2024 |
| Suse | — | Upgrade libwiretap7Upgrade wireshark-develUpgrade libwiretap14Upgrade libwireshark17Upgrade libwsutil13Upgrade libwireshark15Upgrade libwsutil16Upgrade libwiretap12Upgrade libwsutil8Upgrade wireshark-gtkUpgrade wiresharkUpgrade wireshark-ui-qtUpgrade libwiretap15Upgrade libwscodecs1Upgrade libwireshark18Upgrade libwsutil15Upgrade libwireshark9 | Apr 22, 2024 | Feb 21, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub