Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wireshark | Wireshark | 3.6.0 (including) | 3.6.8 (including) |
Wireshark | Ubuntu | bionic | * |
Wireshark | Ubuntu | esm-apps/jammy | * |
Wireshark | Ubuntu | jammy | * |
Wireshark | Ubuntu | kinetic | * |
Wireshark | Ubuntu | lunar | * |
Wireshark | Ubuntu | trusty | * |
Wireshark | Ubuntu | trusty/esm | * |
Wireshark | Ubuntu | upstream | * |
Wireshark | Ubuntu | xenial | * |