CVE-2025-5601
published 2025-06-04CVE-2025-5601: Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.30%
21.6th percentile
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.7-1 | 4.4.7-1 |
| wireshark | wireshark | >= 0 < 4.4.7-1 | 4.4.7-1 |
| wireshark | wireshark | >= 4.2.0 < 4.2.12 | 4.2.12 |
| wireshark | wireshark | >= 4.4.0 < 4.4.7 | 4.4.7 |
| wireshark_foundation | wireshark | >= 4.2.0 < 4.2.13 | 4.2.13 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.7 | 4.4.7 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Buffer Overflow in Wireshark
vendor_redhat·2025-06-04·CVSS 7.8
CVE-2025-5601 [HIGH] CWE-120 wireshark: Buffer Overflow in Wireshark
wireshark: Buffer Overflow in Wireshark
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
A buffer overflow vulnerability was found in Wireshark. This vulnerability is triggered when a user views a specifically malformed packet or a pcap file with such a malformed packet.
Statement: The report makes the assumption that the active user is the root user and calculates the impact based on that assumption. It is not advised to conduct normal operations as the root user and when running as a non-root user, the impact is limited.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and
GitLab
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
vendor_gitlab·2025-06-04·CVSS 6.5
CVE-2025-5601 [MEDIUM] CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
Affected products: Wireshark
Affected versions: >=4.4.0, =4.2.0, <4.2.13 (affected)
Solution: Upgrade to version 4.4.7, 4.2.13 or above.
Debian
CVE-2025-5601: wireshark - Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows d...
vendor_debian·2025·CVSS 7.8
CVE-2025-5601 [HIGH] CVE-2025-5601: wireshark - Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows d...
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.4.7-1)
sid: resolved (fixed in 4.4.7-1)
trixie: resolved (fixed in 4.4.7-1)
GHSA
GHSA-fqw2-jpxp-qh8x: Column handling crashes in Wireshark 4
ghsa_unreviewed·2025-06-04
CVE-2025-5601 [HIGH] CWE-120 GHSA-fqw2-jpxp-qh8x: Column handling crashes in Wireshark 4
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
OSV
CVE-2025-5601: Column handling crashes in Wireshark 4
osv·2025-06-04·CVSS 6.5
CVE-2025-5601 [MEDIUM] CVE-2025-5601: Column handling crashes in Wireshark 4
Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file
No detection rules found.
No public exploits indexed.
2025-06-04
Published