vendor:
Wireshark
by:
Google Security Research
7.5
CVSS
HIGH
Stack-based Buffer Overflow
124
CWE
Product Name: Wireshark
Affected Version From: Wireshark current git master
Affected Version To: Wireshark current git master
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Stack-based Out-of-Bounds Memory Read in Wireshark
A stack-based out-of-bounds memory read vulnerability exists in Wireshark. By feeding a malformed file to tshark, an attacker can trigger a crash due to a stack-based buffer overflow, leading to potential remote code execution or denial of service.
Mitigation:
Apply the latest patch provided by the vendor.