Impact
An uncontrolled recursion bug, accompanied by a buffer management flaw (CWE‑1287), exists in the AFP Spotlight dissector of Wireshark. Maliciously crafted packets can trigger a crash when processed, resulting in a denial of service. The issue is identified as an input handling weakness that maps to both CWE‑674 (Uncontrolled Recursion) and CWE‑1287.
Affected Systems
Wireshark Foundation’s Wireshark application is affected. Versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14 are vulnerable. The issue is present in the AFP Spotlight dissector of these releases.
Risk and Exploitability
CVSS score of 5.5 indicates moderate impact. The EPSS score of 0.007% (equivalent to 7e-05) suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker supplying a crafted AFP Spotlight payload that Wireshark will parse locally, leading to a crash. No remote code execution or elevation is possible; the threat is limited to service disruption for the user.
OpenCVE Enrichment
Debian DSA