Feeds.4Sysops
Wireshark 4.6.8 Addresses 28 Security Bugs, Including Critical File Parser Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Wireshark 4.6.8 has been released, fixing 28 security bugs, with nine vulnerabilities in file parsers that can lead to crashes when opening crafted capture files. These vulnerabilities do not require network access, posing a significant risk to users. The release also addresses memory-safety flaws, two crashes in `sharkd`, and issues with 5G field decoding. Affected file parsers include pcapng, Endace ERF, and several others, particularly on Windows systems. Users are advised to update to the latest version to mitigate these risks. The vulnerabilities could potentially be exploited by attackers to disrupt operations without direct network access. The update is critical for maintaining the integrity and reliability of the protocol analyzer. Current status is that the patch is available and users are encouraged to apply it promptly.
Key Points: • Wireshark 4.6.8 fixes 28 security bugs, including nine in file parsers that can crash the tool. • The vulnerabilities allow crashes from crafted capture files, posing risks without network access. • Users are urged to update to version 4.6.8 to mitigate potential exploitation.