First published: Wed Feb 21 2024(Updated: )
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark | <4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24478 is a denial of service vulnerability that could allow remote attackers to crash the application.
To fix CVE-2024-24478, upgrade Wireshark to version 4.2.0 or later.
CVE-2024-24478 affects versions of Wireshark prior to 4.2.0.
Yes, CVE-2024-24478 can be exploited remotely, resulting in potential denial of service.
Yes, the vendor disputes the vulnerability's impact, claiming that neither release 4.2.0 nor any prior versions were affected.