Impact
The reachable assertion flaw in Wireshark’s BUSMASTER file parser causes an abnormal exit when processing certain file types, resulting in a denial of service that terminates the application and delays packet capture operations. The issue falls under CWE-617, indicating improper control flow handling.
Affected Systems
Wireshark Foundation Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are vulnerable.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score is not available so exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. Based on the description, an attacker who can supply or trick Wireshark into opening a crafted BUSMASTER file can trigger the assertion, causing the application to crash, suggesting a local or remote file input attack vector.
OpenCVE Enrichment