Impact
Wireshark’s ZigBee protocol dissector contains a stack-based buffer overflow that can be triggered by processing malicious ZigBee packets. When the overflow occurs, the Wireshark process crashes, effectively denying service to the user. The weakness is a stack-based buffer overflow (CWE-121) and also involves an input validation flaw (CWE-617).
Affected Systems
The vulnerability affects Wireshark Foundation’s Wireshark product. Versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14 are impacted. An upgrade to 4.6.5 or later resolves the issue.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is <1%, indicating a very low exploitation probability, but not zero. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that Wireshark process ZigBee traffic, so an attacker would need to supply crafted packets or a capture file to a user running Wireshark. The impact is limited to a crash of the application, but repeated crashes could disrupt analysis workflows.
OpenCVE Enrichment
Debian DSA