Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-0209

Опубликовано: 03 янв. 2024
Источник: debian
EPSS Низкий

Описание

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wiresharkfixed4.2.2-1package
wiresharkfixed4.0.17-0+deb12u1bookwormpackage
wiresharkno-dsabusterpackage

Примечания

  • https://www.wireshark.org/security/wnpa-sec-2024-02.html

  • https://gitlab.com/wireshark/wireshark/-/issues/19501

  • The bug references two crashes, this is for the one labelled "BUG log 2",

  • the more severe "Bug log 1" only affected unreleased versions

EPSS

Процентиль: 44%
0.00579
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

CVSS3: 5.5
redhat
больше 2 лет назад

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

CVSS3: 7.8
nvd
больше 2 лет назад

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

CVSS3: 7.8
msrc
около 1 года назад

NULL Pointer Dereference in Wireshark

CVSS3: 7.8
github
больше 2 лет назад

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

EPSS

Процентиль: 44%
0.00579
Низкий