Impact
The vulnerability is a heap‑based buffer overflow in Wireshark’s Catapult DCT2000 protocol dissector. The flaw allows a maliciously crafted packet to overflow a heap buffer, causing the application to crash and thereby denying service to users. It is classified as CWE‑122 and CWE‑476. The denial of service results from unexpected termination of the Wireshark process; it does not provide attackers with remote code execution.
Affected Systems
The affected Wireshark releases are 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. Any system running one of these builds is vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV catalog. Attackers would need to supply crafted DCT2000 packets to a Wireshark instance; the likely vector is by feeding traffic to Wireshark, which could be local or remote, so the likely attack path involves packet capture input. This inference is based on the description that the flaw is triggered by a malformed DCT2000 packet.
OpenCVE Enrichment