PT-2024-3767 · Wireshark+4 · Wireshark+4

Martin Nyhus

·

Published

2024-05-14

·

Updated

2025-03-11

·

CVE-2024-4854

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 4.2.0 through 4.2.4 Wireshark versions 4.0.0 through 4.0.14 Wireshark versions 3.6.0 through 3.6.22
Description The issue is related to infinite loops in the MONGO and ZigBee TLV dissectors, which can cause a denial of service. This can be achieved via packet injection or crafted capture files, allowing a remote attacker to exploit the vulnerability and disrupt service.
Recommendations For Wireshark versions 4.2.0 through 4.2.4, update to a version outside of this range to resolve the issue. For Wireshark versions 4.0.0 through 4.0.14, update to a version outside of this range to resolve the issue. For Wireshark versions 3.6.0 through 3.6.22, update to a version outside of this range to resolve the issue. As a temporary workaround, consider disabling the MONGO and ZigBee TLV dissectors to minimize the risk of exploitation.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-13962
ALT-PU-2024-8022
ALT-PU-2025-3923
AZL-42518
AZL-42564
BDU:2024-04117
CVE-2024-4854
DLA-3906-1
MGASA-2024-0206
OESA-2024-1725
OESA-2024-1726
OESA-2024-1727
OESA-2024-1728
OPENSUSE-SU-2024:13978-1
OPENSUSE-SU-2024_1865-1
OPENSUSE-SU-2024_2265-1
SUSE-SU-2024:1865-1
SUSE-SU-2024:2265-1

Affected Products

Alt Linux
Astra Linux
Red Os
Suse
Wireshark