The latest maintenance release of Wireshark 4.6.7 addresses twelve security vulnerabilities that could affect users who analyze network traffic. Since packets processed in Wireshark pass through numerous protocol analyzers, malformed packets or logs can cause the software to behave unpredictably. The update enhances security by fixing issues in various protocol analyzers, including Catapult DCT2000, SSH, IEEE 802.11 , and other components involved in packet analysis.
See also: Wireshark 4.6.6 fixes ROHC Parser vulnerabilities

Wireshark security fixes cover many protocol analyzers. Most of the dozen vulnerabilities fixed involve software crashes caused by crafted packets or log files. These weaknesses could cause protocol analyzers to read beyond allocated memory or access invalid memory locations, causing Wireshark to terminate unexpectedly.
Affected components include analyzers for Catapult DCT2000, SSH, IEEE 802.11, Z39.50 , and UMTS FP. The security updates also cover the pcapng log reader and the Etherwatch DBS file analyzer, mitigating the risks when opening specially crafted log files.
Some vulnerabilities worked differently than memory-related crashes. The FMP/NOTIFY could enter a long-running processing loop when handling certain inputs, while another patch grouped several parsers that could get stuck in infinite loops. Additionally, the BLF file parser contained an information disclosure issue that could expose data beyond its intended memory limits in the decoded output.
Separate drop vulnerabilities were also addressed in the TLS ECH decryption path and the CiscoDump extcap helper. Additional bug fixes improve the stability of Wireshark. Along with security updates, Wireshark 4.6.7 resolves sixteen non-security bugs that impact stability and usability.
See also: Wireshark vulnerabilities allow system crash

A major fix addresses a use-after-free issue in the Ethernet POWERLINK that occurred during a profile load error. Another fix eliminates a heap buffer overflow in the Android Logcat parser.
The release also resolves several issues that users have encountered. Systems configured for Dutch would incorrectly display the Wireshark interface in German. An IPv6 ping generated by Debian and some other operating systems would be incorrectly identified as HiPerConTracer.
The developers also fixed an issue in the HEVC video parser where some packets were incorrectly marked as garbled due to improper bit shift forwarding. Another fix prevents heap corruption that could cause the application to crash when loading the most recently saved recent_common.
Updated location of extcap binaries for plugin developers. The release also documents a packaging change introduced in Wireshark 4.6.0 that was previously omitted from the official release notes. On UNIX-like systems, Wireshark now looks for the extcap utility binaries in the libexec directory by default, such as /usr/libexec/wireshark/extcap. This location aligns with the standard placement for executable utilities that do not require the multiarch management used for shared libraries.
See also: Wireshark 4.4.4: Fixes vulnerability that triggers DoS attack

The built-in extcap utilities already use the updated directory, although third-party extcap packages may require adjustments to remain compatible. Developers can override the default search path by setting the WIRESHARK_EXTCAP_DIR. The documentation also notes that distributions without a libexec directory, including Alpine Linux, will continue to use the previous binary location.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
