CVE-2024-4854: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4854?
CVE-2024-4854 has a high severity rating, as it allows denial of service through packet injection or crafted capture files.
How do I fix CVE-2024-4854?
To fix CVE-2024-4854, upgrade Wireshark to version 4.2.5 or later, 4.0.15 or later, or 3.6.23 or later.
What versions of Wireshark are affected by CVE-2024-4854?
CVE-2024-4854 affects Wireshark versions 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22.
Can I exploit CVE-2024-4854 remotely?
Yes, CVE-2024-4854 can be exploited remotely via packet injection or by sending specially crafted capture files.
What are the potential consequences of CVE-2024-4854?
The primary consequence of CVE-2024-4854 is the potential for a denial of service attack that disrupts application availability.