PT-2024-3997 · Wireshark+4 · Wireshark+4

Published

2024-05-14

·

Updated

2025-08-05

·

CVE-2024-4853

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions
Wireshark versions prior to 4.2.7-alt1 Wireshark versions prior to 4.4.5-alt1 SUSE Linux 12 SP5 SLE for SAP Apps openSUSE Tumbleweed (libwireshark17-4.2.5-1.1 is affected)
Description
A memory handling issue in the editcap component of Wireshark can lead to a denial of service (DoS) via a crafted capture file. The vulnerability resides in the handle chopping() function and is related to improper memory management. Exploitation of this issue may allow an attacker to cause a service disruption.
Recommendations
Wireshark versions prior to 4.2.7-alt1 should be updated. Wireshark versions prior to 4.4.5-alt1 should be updated. On SUSE Linux 12 SP5, apply patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1522=1. On openSUSE Tumbleweed, update to libwireshark17-4.2.5-1.1 or later.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-13962
ALT-PU-2024-8022
ALT-PU-2025-3923
AZL-43498
AZL-44073
BDU:2024-04416
CVE-2024-4853
DLA-3906-1
MGASA-2024-0206
OESA-2024-1654
OESA-2024-1727
OPENSUSE-SU-2024:13978-1
OPENSUSE-SU-2024_1865-1
OPENSUSE-SU-2024_2265-1
SUSE-SU-2024:1865-1
SUSE-SU-2024:2265-1
SUSE-SU-2024_1865-1
SUSE-SU-2024_2265-1
SUSE-SU-2025:1522-1
SUSE-SU-2025_1522-1

Affected Products

Alt Linux
Astra Linux
Red Os
Suse
Wireshark