CVE-2025-1492

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-1492
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-1492.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-1492
Downstream
Related
Published
2025-02-20T02:15:38Z
Modified
2025-10-17T20:29:41.986291Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file

References

Affected packages

Git / github.com/wireshark/wireshark

Affected ranges

Affected versions

v4.*

v4.2.0
v4.2.1
v4.2.10
v4.2.10rc0
v4.2.1rc0
v4.2.2
v4.2.2rc0
v4.2.3
v4.2.3rc0
v4.2.4
v4.2.4rc0
v4.2.5
v4.2.5rc0
v4.2.6
v4.2.6rc0
v4.2.7
v4.2.7rc0
v4.2.8
v4.2.8rc0
v4.2.9
v4.2.9rc0
v4.4.0
v4.4.1
v4.4.1rc0
v4.4.2
v4.4.2rc0
v4.4.3
v4.4.3rc0

wireshark-4.*

wireshark-4.2.0
wireshark-4.2.1
wireshark-4.2.10
wireshark-4.2.2
wireshark-4.2.3
wireshark-4.2.4
wireshark-4.2.5
wireshark-4.2.6
wireshark-4.2.7
wireshark-4.2.8
wireshark-4.2.9
wireshark-4.4.0
wireshark-4.4.1
wireshark-4.4.2
wireshark-4.4.3