Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-4854


MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file


Published

2024-05-14T15:45:18.890

Last Modified

2025-04-18T16:34:40.553

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-835
  • Type: Primary
    CWE-835

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fedoraproject fedora 39 Yes
Operating System fedoraproject fedora 40 Yes
Application wireshark wireshark ≤ 3.6.22 Yes
Application wireshark wireshark ≤ 4.0.14 Yes
Application wireshark wireshark ≤ 4.2.4 Yes

References