PT-2024-3997 · Wireshark+4 · Wireshark+4
Published
2024-05-14
·
Updated
2025-08-05
·
CVE-2024-4853
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wireshark versions prior to 4.2.7-alt1
Wireshark versions prior to 4.4.5-alt1
SUSE Linux 12 SP5
SLE for SAP Apps
openSUSE Tumbleweed (libwireshark17-4.2.5-1.1 is affected)
Description
A memory handling issue in the
editcap component of Wireshark can lead to a denial of service (DoS) via a crafted capture file. The vulnerability resides in the handle chopping() function and is related to improper memory management. Exploitation of this issue may allow an attacker to cause a service disruption.Recommendations
Wireshark versions prior to 4.2.7-alt1 should be updated.
Wireshark versions prior to 4.4.5-alt1 should be updated.
On SUSE Linux 12 SP5, apply patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1522=1.
On openSUSE Tumbleweed, update to libwireshark17-4.2.5-1.1 or later.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Red Os
Suse
Wireshark