Use-after-free in Wireshark - CVE-2024-4855

 

Use-after-free in Wireshark - CVE-2024-4855

Published: May 16, 2024


Vulnerability identifier: #VU89575
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-4855
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in editcap command line utility. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Wireshark
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Fedora
wireshark
wireshark-help
wireshark-devel
wireshark-debugsource
wireshark-debuginfo
libwireshark15-debuginfo
libwireshark15
wireshark-ui-qt
wireshark-ui-qt-debuginfo
libwiretap12-debuginfo
libwiretap12
libwsutil13
libwsutil13-debuginfo

How to mitigate CVE-2024-4855

Install updates from vendor's website.

Wireshark - addressed in versions 3.6.23, 4.0.15, 4.2.5
wireshark - addressed in versions 3.6.14-8, 3.6.14-9
wireshark-help - addressed in versions 3.6.14-8, 3.6.14-9
wireshark-devel - addressed in versions 3.6.14-8, 3.6.14-9
wireshark-debugsource - addressed in versions 3.6.14-8, 3.6.14-9
wireshark-debuginfo - addressed in versions 3.6.14-8, 3.6.14-9
libwireshark15-debuginfo - update to 3.6.23-150600.18.3.1
libwireshark15 - update to 3.6.23-150600.18.3.1
wireshark - update to 3.6.23-150600.18.3.1
wireshark-ui-qt - update to 3.6.23-150600.18.3.1
wireshark-ui-qt-debuginfo - update to 3.6.23-150600.18.3.1
libwiretap12-debuginfo - update to 3.6.23-150600.18.3.1
wireshark-debugsource - update to 3.6.23-150600.18.3.1
libwiretap12 - update to 3.6.23-150600.18.3.1
libwsutil13 - update to 3.6.23-150600.18.3.1
wireshark-debuginfo - update to 3.6.23-150600.18.3.1
libwsutil13-debuginfo - update to 3.6.23-150600.18.3.1
wireshark-devel - update to 3.6.23-150600.18.3.1
wireshark - addressed in versions 4.0.15-1.fc39, 4.2.5-1.fc40

External References

Related Security Bulletins