Sceawere

Vulnerability Detail

CVE-2026-96419UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Profile Import Buffer Overflow Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:16.640Z",
  "pubdate": "2026-09-29T10:17:16.640Z",
  "executiveSummary": "A critical vulnerability exists in the profile import mechanism, manifesting as a crash during the parsing or deserialization of imported profile data.\nThis flaw is classified as a potential memory corruption vulnerability, enabling Denial of Service (DoS) conditions through application termination.\nThe vulnerability affects versions 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. Due to the nature of the crash, there is a theoretical risk of Remote Code Execution (RCE) if the memory corruption is successfully weaponized by an attacker to overwrite instruction pointers or execute arbitrary payloads.\nExploitation requires the submission of a maliciously crafted profile file to the import interface. Successful exploitation compromises service availability and potentially server integrity.\nOrganizations using the affected versions are at high risk, as an attacker with access to the import functionality can disrupt services or gain unauthorized system control.",
  "technicalDetails": "The vulnerability originates within the profile import module, where the application fails to perform adequate bounds checking or sanitization of input data prior to processing. During the deserialization or parsing phase, providing a specially crafted profile file triggers an exception—likely a heap or stack-based buffer overflow—that results in immediate application termination.\nThe attack flow begins when an attacker provides a crafted payload via the profile import interface. As the application attempts to read the file, the parser encounters an unexpected structure or an oversized field that exceeds pre-allocated memory buffers. This memory corruption overwrites adjacent data structures, corrupting the execution context.\nIf the corruption involves function pointers or return addresses on the stack, the application execution flow can be redirected to attacker-controlled memory segments. This transition from a crash-based Denial of Service to Remote Code Execution is contingent upon the attacker's ability to bypass memory protections such as ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention).\nAffected versions include 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18. The vulnerable component is the subsystem responsible for interpreting and hydrating user profiles from external files. Exploitation typically does not require high-level privileges beyond access to the import feature, though the specific requirements depend on whether the import is exposed to unauthenticated users or restricted to authenticated administrators.\nPost-exploitation, an attacker can achieve a persistent Denial of Service by repeatedly submitting the payload, or gain elevated system access if RCE is achieved. The payload behavior involves a trigger mechanism—likely a malformed header or field sequence—that causes the underlying process to dereference invalid memory addresses, leading to a segmentation fault. The impact is significant as it affects the core functionality of profile management and potentially exposes the underlying host environment to full system compromise."
}