Wireshark 4.6.9 and 4.4.19 Release Patches 35 Vulnerabilities Across Stable and Old Stable Lines
Wireshark shipped two coordinated security updates with version 4.6.9 for its current stable line and 4.4.19 for the older "old stable" branch. Together the two releases close at least 35 vulnerabilities across the protocol dissectors that power the tool, with 19 fixes in 4.6.9 and 16 in 4.4.19. Most bugs are local crashes that require opening a crafted capture file, but several can be triggered remotely and a handful carry RCE potential, including defects flagged by Trend Micro's Zero Day Initiative. The updates add no new features, so the guidance is to patch both installations while verifying the signed tarballs before install.
Wireshark 4.6.9 and 4.4.19 Release Patches 35 Vulnerabilities Across Stable and Old Stable Lines
Wireshark has released two security updates, versions 4.6.9 and 4.4.19, which address at least 35 vulnerabilities across its current and older stable lines. The updates primarily fix local crashes triggered by opening crafted capture files, but some vulnerabilities can be exploited remotely and may lead to remote code execution (RCE). The fixes include common parser errors such as integer overflows and out-of-bounds reads, with notable contributions from several security researchers. Users are advised to update both installations while ensuring the integrity of the signed packages prior to installation
