CVE-2024-4855: Use After Free in editcap
Published May 14, 2024
·Updated
Use after free issue in editcap could cause denial of service via crafted capture file
Affected Software
5 affected components
Wireshark Wireshark>=3.6.0<3.6.23
Wireshark Wireshark>=4.0.0<4.0.15
Wireshark Wireshark>=4.2.0<4.2.5
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.5
Event History
May 14, 2024
CVE Published
via MITRE·12:03 AM
Data Sourced
via MITRE·12:03 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:45 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4855?
CVE-2024-4855 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2024-4855?
To fix CVE-2024-4855, update Wireshark to version 3.6.23 or later, 4.0.15 or later, or 4.2.5 or later.
3
Which versions of Wireshark are affected by CVE-2024-4855?
CVE-2024-4855 affects Wireshark versions from 3.6.0 to 3.6.23, 4.0.0 to 4.0.15, and 4.2.0 to 4.2.5.
4
What is the impact of CVE-2024-4855?
The impact of CVE-2024-4855 is that it can lead to a denial of service condition when processing crafted capture files.
5
Is CVE-2024-4855 specific to certain operating systems?
CVE-2024-4855 affects Wireshark installations on Fedora versions 39 and 40.