First published: Thu Feb 20 2025(Updated: )
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark | >=4.4.0<4.4.3>=4.2.0<4.2.10 |
Upgrade to version 4.4.4, 4.2.11 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1492 is classified as a denial of service vulnerability that affects specific versions of Wireshark.
To fix CVE-2025-1492, upgrade Wireshark to a version later than 4.4.3 or 4.2.10.
CVE-2025-1492 affects Wireshark versions 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10.
CVE-2025-1492 allows denial of service attacks via packet injection or using crafted capture files.
Yes, CVE-2025-1492 can be exploited remotely if an attacker can send crafted packets to a vulnerable Wireshark installation.