CVE-2024-4854
6.4MEDIUMMONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
Publicado: 5/14/2024Atualizado: 11/3/2025
Descrição
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
Análise IADesenvolvido por IA
Produtos Afetados
fedoraprojectfedora
39
fedoraprojectfedora
40
wiresharkwireshark
wiresharkwireshark
wiresharkwireshark
Referências
- https://gitlab.com/wireshark/wireshark/-/issues/19726Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15047Product
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15499Product
- https://www.wireshark.org/security/wnpa-sec-2024-07.htmlVendor Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/19726Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15047Product
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15499Product
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/Mailing List
- https://www.wireshark.org/security/wnpa-sec-2024-07.htmlVendor Advisory