CVE-2025-5601Classic Buffer Overflow in Foundation Wireshark

Severity
6.5MEDIUMNVD
CNA7.8
EPSS
0.1%
top 66.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4

Description

Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDwireshark/wireshark4.2.04.2.12+1
CVEListV5wireshark_foundation/wireshark4.4.04.4.7+1
Debianwireshark/wireshark< 3.4.16-0+deb11u2+2

🔴Vulnerability Details

3
GHSA
GHSA-fqw2-jpxp-qh8x: Column handling crashes in Wireshark 42025-06-04
CVEList
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark2025-06-04
OSV
CVE-2025-5601: Column handling crashes in Wireshark 42025-06-04

📋Vendor Advisories

2
Red Hat
wireshark: Buffer Overflow in Wireshark2025-06-04
Debian
CVE-2025-5601: wireshark - Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows d...2025
CVE-2025-5601 — Classic Buffer Overflow | cvebase