#22473 closed enhancement (fixed)
wireshark-4.6.2 (Security issue)
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (7)
comment:1 by , 10 months ago
| Priority: | normal → elevated |
|---|---|
| Summary: | wireshark-4.6.2 → wireshark-4.6.2 (Security issue) |
comment:2 by , 10 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 10 months ago
Name: HTTP3 dissector crash Docid: wnpa-sec-2025-07 Date: December 3, 2025 Affected versions: 4.6.0 to 4.6.1 Fixed versions: 4.6.2 Wireshark issue 20860. CVE-2025-13945.
Name: MEGACO dissector infinite loop Docid: wnpa-sec-2025-08 Date: December 3, 2025 Affected versions: 4.6.0 to 4.6.1, 4.4.0 to 4.4.11 Fixed versions: 4.6.2, 4.4.12 Wireshark issue 20884. CVE-2025-13946.
comment:4 by , 10 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at commits
2f2db1cbfa Update to wireshark-4.6.2 (Security issue). new 7cf63d9041 Update to httpd-2.4.66 (Security issue).
Leaving open for security advisories.
comment:5 by , 10 months ago
| Status: | new → assigned |
|---|
Note:
See TracTickets
for help on using tickets.

Wireshark 4.6.2 Release Notes
Bug Fixes
This release fixes an API/ABI change that was introduced in Wireshark 4.6.1, which caused a compatibility issue with plugins built for Wireshark 4.6.0.
The following vulnerabilities have been fixed:
The following bugs have been fixed:
New and Updated Features