Wireshark has released version 4.6.7, a maintenance update that fixes 12 security vulnerabilities affecting the processing of untrusted packets and capture or trace files. The flaws primarily allowed crashes through out-of-bounds reads, invalid memory access, and large or infinite processing loops triggered by crafted network traffic or malformed files, while one issue in the BLF parser could lead to information disclosure.
The patched areas span multiple protocol dissectors and parsers, including Catapult DCT2000, SSH, IEEE 802.11, Z39.50, UMTS FP, the pcapng reader, DBS Etherwatch, the TLS ECH decryption path, and the CiscoDump extcap helper. The release also fixes 16 non-security bugs, updates several protocol handlers, and notes that on Unix-like systems, extcap binaries are now searched under the libexec directory by default.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Wireshark released version 4.6.7 as a maintenance update that fixes twelve security vulnerabilities affecting multiple protocol dissectors and capture-file parsers that process untrusted packet and trace data. The issues included crash-causing out-of-bounds reads, invalid memory access, infinite or large loops, and an information disclosure flaw in the BLF parser.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
isc.sans.edu
Open sourcethecyberexpress.com
Open sourcehelpnetsecurity.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.