CVE Vulnerabilities

CVE-2024-9780

Missing Initialization of a Variable

Published: Oct 10, 2024 | Modified: Oct 17, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

Weakness

The product does not initialize critical variables, which causes the execution environment to use unexpected values.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark4.4.0 (including)4.4.0 (including)
WiresharkUbuntuesm-apps/focal*
WiresharkUbuntuesm-apps/jammy*
WiresharkUbuntuesm-apps/noble*
WiresharkUbuntufocal*
WiresharkUbuntujammy*
WiresharkUbuntunoble*
WiresharkUbuntuoracular*
WiresharkUbuntutrusty/esm*
WiresharkUbuntuupstream*

Potential Mitigations

References