Impact
The vulnerability is a heap-based buffer overflow in the Catapult DCT2000 file parser of Wireshark, which can cause the application to crash when processing malformed files. This crash leads to a denial of service, allowing an adversary to disrupt network traffic analysis by simply opening a crafted file. The weakness corresponds to CWE‑122.
Affected Systems
Wireshark Foundation’s Wireshark product is affected. The vulnerability exists in versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. Users who are running any of these releases are susceptible to the denial of service attack described.
Risk and Exploitability
The CVSS score of 4.7 indicates a low‑to‑medium severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; an attacker can supply a malicious Catapult DCT2000 file to a victim’s instance of Wireshark or use a social engineering technique to trick a user into opening the file.
OpenCVE Enrichment
Debian DSA