CVE-2024-4854
6.4MEDIUMMONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
Опубликовано: 5/14/2024Обновлено: 11/3/2025
Описание
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
ИИ-АнализНа базе ИИ
Затронутые продукты
fedoraprojectfedora
39
fedoraprojectfedora
40
wiresharkwireshark
wiresharkwireshark
wiresharkwireshark
Ссылки
- https://gitlab.com/wireshark/wireshark/-/issues/19726Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15047Product
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15499Product
- https://www.wireshark.org/security/wnpa-sec-2024-07.htmlVendor Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/19726Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15047Product
- https://gitlab.com/wireshark/wireshark/-/merge_requests/15499Product
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/Mailing List
- https://www.wireshark.org/security/wnpa-sec-2024-07.htmlVendor Advisory