ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
History

Fri, 22 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
Vendors & Products Wireshark
Wireshark wireshark
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 21 Nov 2024 09:45:00 +0000

Type Values Removed Values Added
Description ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
Title Buffer Over-read in Wireshark
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2024-11-21T09:30:59.843Z

Updated: 2024-11-22T15:41:11.586Z

Reserved: 2024-11-21T09:30:49.862Z

Link: CVE-2024-11596

cve-icon Vulnrichment

Updated: 2024-11-22T15:41:06.136Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-21T11:15:33.350

Modified: 2024-11-21T13:57:24.187

Link: CVE-2024-11596

cve-icon Redhat

Severity : Important

Publid Date: 2024-11-21T09:30:59Z

Links: CVE-2024-11596 - Bugzilla