Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0211

Опубликовано: 03 янв. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

A flaw was found in the DOCSIS dissector of Wireshark. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Отчет

Red Hat Enterprise Linux 6, 7, 8 and 9 are not affected by this CVE as they shipped an older version of Wireshark that did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wiresharkNot affected
Red Hat Enterprise Linux 7wiresharkNot affected
Red Hat Enterprise Linux 8wiresharkNot affected
Red Hat Enterprise Linux 9wiresharkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2256652wireshark: DOCSIS dissector crash via packet injection or crafted capture file

EPSS

Процентиль: 24%
0.00082
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

CVSS3: 7.8
nvd
около 2 лет назад

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

CVSS3: 7.8
debian
около 2 лет назад

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via ...

CVSS3: 7.8
github
около 2 лет назад

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

suse-cvrf
больше 1 года назад

Security update for wireshark

EPSS

Процентиль: 24%
0.00082
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2024-0211