Impact
A buffer over-read bug in the ERF file parser of Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 causes the application to crash when parsing malformed ERF files, resulting in a denial of service. The flaw triggers when input data extends beyond the allocated buffer boundaries, which leads to an ungainly termination of the program without any exploit code execution or data exfiltration.
Affected Systems
The vulnerability affects Wireshark Foundation’s Wireshark product, specifically releases 4.6.0‑4.6.7 and 4.4.0‑4.4.18. Users running any of these versions and opening ERF files from untrusted or potentially corrupted sources are at risk.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity; the EPSS score of < 1% suggests a very low probability of exploitation, and the lack of a KEV listing further reduces the urgency. Based on the description, the attack vector is limited to locally opening a crafted ERF file, which implies that only users or processes with access to such files can trigger the denial of service. Consequently, the risk is considered low but mitigable through updating the software.
OpenCVE Enrichment
Debian DSA