Security update: Attackers can crash network analysis tool Wireshark
Wireshark has been released in a version secured against possible attacks. The developers have also fixed several bugs.
(Image: AFANASEV IVAN/Shutterstock.com)
Attackers can target the network analysis tool Wireshark and cause it to crash after successful attacks.
Closed security vulnerabilities
In an article on the current version of Wireshark 4.4.1, the developers assure that they have closed the two security vulnerabilities (CVE-2024-9780"high", CVE-2024-9781"high"). So far, according to them, there are no indications that attacks are already underway.
Videos by heise
In both cases, attackers can cause certain components (AppleTalk, ITS, reload framing) to crash in the course of a DoS attack by sending prepared packets.
The developers have also fixed several bugs. According to the changelog, Bluetooth problems have been solved, among other things. There are also updates for protocols such as BT L2CAP and TWAMP.
(des)