Impact
A buffer over-read condition was discovered in the Tektronix K12xx file parser of Wireshark, which can cause the application to crash and lead to a denial of service. The flaw allows an attacker to trigger the crash by presenting a specially crafted K12xx file, resulting in loss of service availability – an impact described by CWE‑126.
Affected Systems
The vulnerability affects Wireshark products distributed by the Wireshark Foundation. The affected releases are Wireshark 4.6.0 through 4.6.7 and Wireshark 4.4.0 through 4.4.18.
Risk and Exploitability
The CVSS base score of 3.1 indicates a low severity impact. No EPSS score is available and the CVE is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply a malicious Tektronix K12xx file to a user running Wireshark, either locally or via a remote service that processes user files. Because the flaw manifests only when Wireshark parses the file, the attack surface is limited to environments where the application processes untrusted input.
OpenCVE Enrichment