ON
← Back to feed
Numerous crash holes in Wireshark closed
Germany💻 Technology6 days ago

Numerous crash holes in Wireshark closed

Ein Sicherheitsupdate für das Netzwerkanalysetool Wireshark hat 28 potenzielle DoS-Lücken geschlossen, darunter Schwachstellen im Zusammenhang mit Bluetooth, RDP und SSH. Angreifer könnten theoretisch durch gezielte Angriffe wie präparierte RDP-Anfragen Systeme zum Absturz bringen. Die Entwickler haben dies in den Release Notes der Version 4.6.8 dokumentiert, jedoch wurden keine konkreten CVE-Nummern oder Bedrohungsgrade genannt. Bisher gibt es keine Hinweise darauf, dass diese Schwachstellen bereits ausgenutzt werden. Ein Sicherheitsupdate wird empfohlen, um Risiken zu minimieren.

Multiple critical vulnerabilities that could cause crashes in the network analysis tool Wireshark have been patched, according to a recent update. The security fixes address 28 denial-of-service (DoS) flaws identified in version 4.6.8 of the software. While the developers have not yet reported evidence of these vulnerabilities being exploited in the wild, they warn that attackers could potentially trigger system crashes by exploiting them under specific conditions. The vulnerabilities affect different protocols including Bluetooth, Remote Desktop Protocol (RDP), and Secure Shell (SSH). Attackers would need to send specially crafted RDP requests to vulnerable systems in order to induce a crash. The exact nature of each flaw has not been detailed with specific Common Vulnerabilities and Exposures (CVE) identifiers, though the release notes confirm the number of issues addressed. This latest patch follows a series of security updates released earlier this year. In May, the Wireshark team had already closed several other security holes, demonstrating their ongoing commitment to maintaining the integrity and stability of the widely used open-source tool. The frequency of such updates underscores the importance of keeping network analysis tools up-to-date, especially given the potential for malicious actors to exploit known weaknesses. Wireshark, developed by the Wireshark Foundation, is a popular utility among cybersecurity professionals and network administrators for capturing and analyzing data packets. Its widespread usage makes it a target for both ethical hackers and malicious entities seeking to compromise network infrastructure. As a result, regular security audits and prompt patching of vulnerabilities are essential to safeguard against potential attacks. Security experts recommend users immediately apply the latest update to ensure protection against the newly fixed flaws. The absence of confirmed exploitation attempts does not eliminate the risk, particularly as the tools required to exploit these vulnerabilities remain accessible to those with technical expertise. Organizations relying on Wireshark for monitoring and troubleshooting network traffic should prioritize applying the patches to maintain operational resilience. The Wireshark community continues to monitor the situation closely, with plans to provide further updates as needed. Until then, users are advised to stay informed and follow best practices for securing their network analysis environments. The continued efforts of the development team highlight the dynamic nature of cybersecurity threats and the necessity for proactive defense strategies.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 75Objective 706 days ago
Numerous crash holes in Wireshark closed

Ein Sicherheitsupdate für das Netzwerkanalysetool Wireshark hat 28 potenzielle DoS-Lücken geschlossen, darunter Schwachstellen im Zusammenhang mit Bluetooth, RDP und SSH. Angreifer könnten theoretisch durch gezielte Angriffe wie präparierte RDP-Anfragen Systeme zum Absturz bringen. Die Entwickler haben dies in den Release Notes der Version 4.6.8 dokumentiert, jedoch wurden keine konkreten CVE-Nummern oder Bedrohungsgrade genannt. Bisher gibt es keine Hinweise darauf, dass diese Schwachstellen bereits ausgenutzt werden. Ein Sicherheitsupdate wird empfohlen, um Risiken zu minimieren.

Bias read (Center): Das Thema betrifft technische Sicherheitsupdates und ist politisch unbelastet. Es handelt sich um eine objektive Meldung über Schwachstellen und deren Behebung ohne einseitige Bewertung oder politischen Kontext.

Why factuality (75): The article mentions 28 DoS vulnerabilities were closed but does not provide specific CVE identifiers, which are absent in the primary source. It accurately references the release notes and describes some of the affected protocols such as Bluetooth, RDP, and SSH. However, it lacks precise details on

Why objectivity (70): The article uses terms like 'Angreifer' (attackers) and implies potential exploitation, which may introduce a slight bias towards threat perception. The tone is generally neutral but could be seen as slightly alarmist due to the emphasis on potential attacks.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories