CVE-2024-0208: Improper Handling of Missing Values in Wireshark
Published Jan 3, 2024
·Updated
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
Affected Software
3 affected components
Wireshark Wireshark>=3.6.0<=3.6.19
Wireshark Wireshark>=4.0.0<=4.0.11
Wireshark Wireshark=4.2.0
Remediation
Information
Upgrade to versions 4.2.0, 4.0.12, 3.6.20 or above.
Event History
Jan 3, 2024
CVE Published
07:31 AM
Data Sourced
07:31 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-0208?
CVE-2024-0208 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2024-0208?
To fix CVE-2024-0208, users should upgrade Wireshark to version 4.2.1 or later, or to version 4.0.12 or 3.6.20.
3
What versions of Wireshark are affected by CVE-2024-0208?
CVEs 4.2.0, 4.0.0 through 4.0.11, and 3.6.0 through 3.6.19 of Wireshark are impacted by CVE-2024-0208.
4
What potential impact does CVE-2024-0208 have?
CVE-2024-0208 allows for a denial of service condition, which can be triggered via packet injection or a crafted capture file.
5
Is there a workaround for CVE-2024-0208?
There is no official workaround for CVE-2024-0208 aside from upgrading to the patched versions of Wireshark.