CVE-2024-9780: Missing Initialization of a Variable in Wireshark
Published Oct 10, 2024
·Updated
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
Affected Software
1 affected component
Wireshark Wireshark=4.4.0
Remediation
Information
Upgrade to version 4.4.1 or above.
Event History
Oct 10, 2024
CVE Published
via MITRE·06:30 AM
Data Sourced
via MITRE·06:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9780?
CVE-2024-9780 is categorized as a denial of service vulnerability due to a crash in the ITS dissector.
2
How do I fix CVE-2024-9780?
To fix CVE-2024-9780, upgrade to Wireshark version 4.4.1 or later.
3
What causes the CVE-2024-9780 vulnerability?
CVE-2024-9780 is caused by a crash in Wireshark's ITS dissector when processing crafted packets or capture files.
4
Can CVE-2024-9780 be exploited remotely?
Yes, CVE-2024-9780 can be exploited remotely through packet injection or by using crafted capture files.
5
Which versions of Wireshark are affected by CVE-2024-9780?
CVE-2024-9780 specifically affects Wireshark version 4.4.0.