CVE-2024-4854
6.4MEDIUMMONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
게시됨: 5/14/2024업데이트됨: 11/3/2025
설명
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
AI 분석AI 기반
영향받는 제품
fedoraprojectfedora
39
fedoraprojectfedora
40
wiresharkwireshark
wiresharkwireshark
wiresharkwireshark
참조
- https://gitlab.com/wireshark/wireshark/-/issues/19726Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15047Product
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15499Product
- https://www.wireshark.org/security/wnpa-sec-2024-07.htmlVendor Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/19726Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15047Product
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15499Product
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/Mailing List
- https://www.wireshark.org/security/wnpa-sec-2024-07.htmlVendor Advisory