CVE Vulnerabilities

CVE-2024-8250

Expired Pointer Dereference

Published: Aug 29, 2024 | Modified: Nov 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

Weakness

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark4.0.0 (including)4.0.17 (excluding)
WiresharkWireshark4.2.0 (including)4.2.7 (excluding)
WiresharkUbuntuesm-apps/bionic*
WiresharkUbuntuesm-apps/focal*
WiresharkUbuntuesm-apps/jammy*
WiresharkUbuntuesm-apps/noble*
WiresharkUbuntuesm-apps/xenial*
WiresharkUbuntuesm-infra-legacy/trusty*
WiresharkUbuntufocal*
WiresharkUbuntujammy*
WiresharkUbuntunoble*
WiresharkUbuntuoracular*
WiresharkUbuntutrusty/esm*
WiresharkUbuntuupstream*

Potential Mitigations

References