An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
References
Configurations
No configuration.
History
21 Nov 2024, 08:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/1047524396/e82c55147cd3cb62ef20cbdb0ec83694 - | |
References | () https://github.com/wireshark/wireshark/commit/80a4dc55f4d2fa33c2b36a99406500726d3faaef - | |
References | () https://gitlab.com/wireshark/wireshark/-/issues/19347 - |
01 Aug 2024, 13:47
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-680 |
23 Feb 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. |
22 Feb 2024, 19:07
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Feb 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-21 17:15
Updated : 2024-11-21 08:59
NVD link : CVE-2024-24478
Mitre link : CVE-2024-24478
CVE.ORG link : CVE-2024-24478
JSON object : View
Products Affected
No product.
CWE
CWE-680
Integer Overflow to Buffer Overflow