A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
2024-02-21T19:15:09.077
2025-04-14T12:55:40.677
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | wireshark | wireshark | < 4.2.0 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |