Impact
This vulnerability is a stack‑based buffer overflow in the Gammu DCT3 trace file parser of Wireshark. When a malformed trace file is parsed, the overflow causes the application to crash, resulting in a denial of service. The flaw is identified as CWE‑121 and leads to loss of availability for users relying on Wireshark for packet analysis.
Affected Systems
Affected versions are Wireshark 4.6.0 through 4.6.7. The product is Wireshark from Wireshark Foundation. Upgrading to version 4.6.8 or later eliminates the flaw.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity. Because the exploit requires the ability to supply a crafted Gammu DCT3 trace file, the attack vector is local and file‑based; remote exploitation was not documented. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nevertheless, any environment that processes untrusted trace files should address the flaw promptly.
OpenCVE Enrichment