Executive brief
Wireshark, a widely used network protocol analyzer, is vulnerable to a crash when processing specifically crafted Catapult DCT2000 network trace files. An attacker could provide a malicious capture file to a user, which, when opened, causes the application to crash and stop functioning. This results in a denial of service, potentially disrupting network troubleshooting or security analysis activities.
Technical details
A heap-based buffer overflow exists in the Catapult DCT2000 protocol dissector (epan/dissectors/packet-catapult-dct2000.c) within the attach_fp_info() function. The vulnerability is caused by a lack of bounds checking on the 'no_ddi_entries' value read from a capture file header. An attacker can provide a crafted Catapult/DCT2000 text capture with an excessively large 'no_ddi_entries' value, causing subsequent loops to write past the fixed-size 'edch_ddi' and 'edch_macd_pdu_size' arrays. This corrupts the wmem block allocator's metadata, leading to a segmentation fault (SIGSEGV) during subsequent memory allocations. The issue is addressed by capping the 'no_ddi_entries' value at MAX_EDCH_DDIS.
Affected products
- Wireshark Foundation Wireshark 4.6.0 to 4.6.6, 4.4.0 to 4.4.16
Timeline
- 2026-07-08: advisory: NVD publication date