Impact
A buffer overflow occurs while parsing Ixia IxVeriWave and Vector Informatik BLF files in Wireshark versions 4.6.0 through 4.6.7. The flaw leads to an out‑of‑bounds write (CWE-787) that can crash the application and cause a denial of service on Windows systems when a malicious file is processed. The crash is limited to the Wireshark process and does not directly provide arbitrary code execution or remote influence, but it can disrupt network monitoring services.
Affected Systems
The vulnerability affects Wireshark Foundation’s Wireshark product, specifically releases 4.6.0 to 4.6.7. Updated versions 4.6.8 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity. There is no EPSS score available and the vulnerability is not listed in CISA’s KEV catalog, suggesting the exploitation landscape is limited or not yet observed. Attackers are likely to trigger the flaw by providing a crafted BLF file to a Windows installation of Wireshark, which may be feasible if the user opens an untrusted capture file. Because the issue does not provide remote code execution, the risk is confined to local denial of service.
OpenCVE Enrichment