MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-3906-1 | wireshark security update | 
  EUVD | 
                EUVD-2024-44432 | MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file | 
Fixes
    Solution
Upgrade to versions 4.2.5 or above.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Mon, 03 Nov 2025 23:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 18 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Fedoraproject
         Fedoraproject fedora Wireshark Wireshark wireshark  | 
|
| CPEs | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* cpe:2.3:a:wireshark:wireshark:*:-:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Fedoraproject
         Fedoraproject fedora Wireshark Wireshark wireshark  | 
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-03T22:22:02.062Z
Reserved: 2024-05-14T00:02:57.493Z
Link: CVE-2024-4854
Updated: 2025-11-03T22:22:02.062Z
Status : Modified
Published: 2024-05-14T15:45:18.890
Modified: 2025-11-03T23:16:38.747
Link: CVE-2024-4854
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 EUVD