Impact
This vulnerability is a stack‑based buffer overflow in the HTTP protocol dissector of Wireshark. Versions 4.6.0–4.6.4 and 4.4.0–4.4.14 can be triggered by a maliciously crafted HTTP packet, causing the application to crash and leading to a denial of service. The weakness is categorized as CWE‑121 and CWE‑617, a classic stack buffer overflow and an improper restriction of operations within the bounds of a memory buffer.
Affected Systems
The affected product is Wireshark from Wireshark Foundation. The vulnerability affects Wireshark releases 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. An upgrade to version 4.6.5 or later resolves the issue.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a crafted HTTP packet to a running Wireshark instance, which is feasible when Wireshark loads live traffic. Successful exploitation would crash the application, causing denial of service to the analyst or end‑user who relies on Wireshark for network captures.
OpenCVE Enrichment
Debian DSA