CVE-2024-11595: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published Nov 21, 2024
·Updated
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
Affected Software
3 affected components
Wireshark Wireshark>=4.4.0<4.4.1, >=4.2.0<4.2.8
Wireshark Wireshark>=4.2.0<4.2.9
Wireshark Wireshark>=4.4.0<4.4.2
Remediation
Information
Upgrade to version 4.4.2, 4.2.9 or above.
Event History
Nov 21, 2024
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-11595?
CVE-2024-11595 is classified as a denial of service vulnerability due to the infinite loop in the FiveCo RAP dissector.
2
How do I fix CVE-2024-11595?
To fix CVE-2024-11595, update your Wireshark installation to version 4.4.2 or later, or to version 4.2.9 or later.
3
What versions of Wireshark are affected by CVE-2024-11595?
Wireshark versions 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 are affected by CVE-2024-11595.
4
Can CVE-2024-11595 be exploited remotely?
Yes, CVE-2024-11595 can be exploited through packet injection or crafted capture files.
5
What happens when CVE-2024-11595 is triggered?
When CVE-2024-11595 is triggered, it results in an infinite loop that can cause Wireshark to become unresponsive.