Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://www.wireshark.org/security/wnpa-sec-2022-08.html | vendor advisory |
https://gitlab.com/wireshark/wireshark/-/issues/18384 | issue tracking third party advisory |
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3724.json | third party advisory |