PT-2024-1856 · Wireshark+1 · Wireshark+1
Published
2024-02-21
·
Updated
2024-08-29
·
CVE-2024-24479
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark versions prior to 4.2.0
Description
The issue is related to a buffer overflow in the
format fractional part nsecs function of Wireshark, which can be exploited by a remote attacker to cause a denial of service. This is due to the lack of size checking for input data during the buffer copying process. The exploitation of this issue may allow a remote attacker to disrupt the service.Recommendations
For Wireshark versions prior to 4.2.0, as a temporary workaround, consider disabling the
format fractional part nsecs function until a patch is available. However, since the vendor disputes the vulnerability, stating that neither release 4.2.0 nor any other release was affected, it is essential to monitor official Wireshark updates for any further information regarding this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Os
Wireshark