CVE Vulnerabilities

CVE-2024-9781

Improper Handling of Missing Values

Published: Oct 10, 2024 | Modified: Nov 25, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

Weakness

The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 4.2.0 (including) 4.2.8 (excluding)
Wireshark Wireshark 4.4.0 (including) 4.4.0 (including)
Wireshark Ubuntu trusty/esm *

References