CVE Vulnerabilities

CVE-2024-9781

Improper Handling of Missing Values

Published: Oct 10, 2024 | Modified: Nov 25, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

Weakness

The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark4.2.0 (including)4.2.8 (excluding)
WiresharkWireshark4.4.0 (including)4.4.0 (including)
WiresharkUbuntuesm-apps/bionic*
WiresharkUbuntuesm-apps/focal*
WiresharkUbuntuesm-apps/jammy*
WiresharkUbuntuesm-apps/noble*
WiresharkUbuntuesm-apps/xenial*
WiresharkUbuntuesm-infra-legacy/trusty*
WiresharkUbuntufocal*
WiresharkUbuntujammy*
WiresharkUbuntunoble*
WiresharkUbuntuoracular*
WiresharkUbuntutrusty/esm*
WiresharkUbuntuupstream*

References