Impact
A heap‑based buffer overflow has been identified in the UMTS FP protocol dissector of Wireshark. When a user opens or imports a capture file that contains a specially crafted UMTS FP packet, the overflow causes the application to crash, resulting in denial of service. The flaw is a classic buffer overflow (CWE‑122) that disrupts the availability of the Wireshark process for the user and has no known effect on data confidentiality or privilege escalation.
Affected Systems
The vulnerable releases are Wireshark Foundation Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. All other Wireshark releases are not affected.
Risk and Exploitability
With a CVSS score of 5.5 the vulnerability is of moderate severity. The EPSS score is reported as < 1 %, indicating a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be the delivery of a malicious capture file that triggers the UMTS FP dissector, causing a controlled crash and a denial of service for the victim user.
OpenCVE Enrichment