PT-2022-13281 · Wireshark+5 · Wireshark+5

Sharon Brizinov

·

Published

2022-02-14

·

Updated

2025-06-04

·

CVE-2022-0586

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.4.0 through 3.4.11 Wireshark versions 3.6.0 through 3.6.1
Description The issue is related to an infinite loop in the RTMPT protocol dissector, which can be exploited to cause a denial of service. This can be achieved through packet injection or by using a crafted capture file.
Recommendations For Wireshark versions 3.4.0 through 3.4.11, update to a version that contains a fix for this issue. For Wireshark versions 3.6.0 through 3.6.1, update to a version that contains a fix for this issue. As a temporary workaround, consider disabling the RTMPT protocol dissector until a patch is available.

Exploit

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1349
ALT-PU-2022-1368
ALT-PU-2022-1391
ALT-PU-2022-1599
AZL-8614
CVE-2022-0586
DLA-2967-1
DLA-3906-1
OESA-2022-2078
OPENSUSE-SU-2022:0722-1
OPENSUSE-SU-2022_0722-1
OPENSUSE-SU-2024:11858-1
SUSE-SU-2022:0722-1
USN-7552-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wireshark