Denial of Service Vulnerability in Wireshark by The Wireshark Foundation
CVE-2022-0583
7.5HIGH
Summary
A vulnerability exists in the PVFS protocol dissector in Wireshark versions 3.4 and 3.6, enabling attackers to exploit crafted packets or capture files. This flaw can trigger crashes, potentially disrupting service and compromising the reliability of network analysis tools.
Affected Version(s)
Wireshark >=3.6.0, <3.6.2 < 3.6.0, 3.6.2
Wireshark >=3.4.0, <3.4.12 < 3.4.0, 3.4.12
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sharon Brizinov