Impact
The vulnerability arises from an uninitialized variable in Wireshark’s BLF file parser. When a BLF file is processed, the parser may expose data that had not been initialized, potentially leaking sensitive information from the program’s memory. This weakness is classified under CWE‑237 and CWE‑457 and could compromise confidentiality of user or system data.
Affected Systems
Wireshark packets analyzer from the Wireshark Foundation is affected. Versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16 contain the flaw. Versions newer than 4.6.6 or older than 4.4.0 are not impacted.
Risk and Exploitability
The CVSS score of 2.5 indicates a low severity assessment. The EPSS score of <1% shows a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or nearby, requiring a malicious BLF file to be opened by a user of Wireshark. Because the flaw needs crafted input rather than remote code execution, widespread exploitation is unlikely.
OpenCVE Enrichment