Impact
A heap‑based buffer overflow exists in the DCP‑ETSI protocol dissector of Wireshark. The flaw can be triggered by processing maliciously crafted data, leading to a crash of the Wireshark application and resulting in a denial of service. The vulnerability maps to CWE-122, illustrating an unchecked input handling weakness that causes an out‑of‑bounds write on the heap, and also to CWE-476, indicating a null pointer dereference that can lead to application termination.
Affected Systems
The issue affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Users of these releases are at risk of an application crash whenever the DCP‑ETSI dissector processes invalid packets.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. The likely attack vector is local; an attacker must supply malformed packet data that Wireshark will parse. Without remote code execution, the primary consequence is disruption of capturing activities by causing the application to terminate.
OpenCVE Enrichment
Debian DSA