CVE Vulnerabilities

CVE-2024-8250

Expired Pointer Dereference

Published: Aug 29, 2024 | Modified: Aug 30, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

Weakness

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 4.0.0 (including) 4.0.17 (excluding)
Wireshark Wireshark 4.2.0 (including) 4.2.7 (excluding)
Wireshark Ubuntu trusty/esm *

Potential Mitigations

References