PT-2024-6607 · Wireshark+3 · Wireshark+3

Vocal-Daves

·

Published

2024-01-02

·

Updated

2024-10-12

·

CVE-2024-8645

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Wireshark versions 4.2.0 through 4.0.5 Wireshark versions 4.0.0 through 4.0.15
Description: The issue is related to a crash in the SPRT dissector of Wireshark, which can be exploited to cause a denial of service. This can be achieved via packet injection or by using a crafted capture file. The vulnerability is associated with access to an uninitialized pointer, and its exploitation may allow an attacker to disrupt service by sending specially formed RTP packets.
Recommendations: For Wireshark versions 4.2.0 through 4.0.5, update to a version that fixes the SPRT dissector crash issue. For Wireshark versions 4.0.0 through 4.0.15, update to a version that fixes the SPRT dissector crash issue. As a temporary workaround, consider disabling the SPRT dissector until a patch is available.

Exploit

Fix

DoS

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

AZL-48987
AZL-49021
BDU:2024-07760
CVE-2024-8645
DLA-3906-1
OESA-2024-2242
OPENSUSE-SU-2024:14341-1
OPENSUSE-SU-2024_3250-1
SUSE-SU-2024:3250-1

Affected Products

Astra Linux
Red Os
Suse
Wireshark