CVE Vulnerabilities

CVE-2024-9780

Missing Initialization of a Variable

Published: Oct 10, 2024 | Modified: Oct 17, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

Weakness

The product does not initialize critical variables, which causes the execution environment to use unexpected values.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 4.4.0 (including) 4.4.0 (including)
Wireshark Ubuntu trusty/esm *

Potential Mitigations

References