REDHAT-BUG-2464276: Path Traversal
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Avoid importing Wireshark profiles from untrusted sources and do not open profile files obtained from untrusted or unknown origins. Restrict the exchange of .zip/.profile files used for Wireshark profiles and treat profile imports as untrusted content until a vendor fix or advisory is available.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2464276?
The severity of REDHAT-BUG-2464276 is rated high with a score of 7.
What software is affected by REDHAT-BUG-2464276?
Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 are affected by REDHAT-BUG-2464276.
What type of vulnerability is REDHAT-BUG-2464276?
REDHAT-BUG-2464276 is classified as a path traversal vulnerability.
What impact does REDHAT-BUG-2464276 have?
REDHAT-BUG-2464276 can lead to denial of service and possible code execution.
How do I mitigate the risks of REDHAT-BUG-2464276?
To mitigate the risks of REDHAT-BUG-2464276, upgrade to the patched versions of Wireshark as specified in the security advisories.