2024-05-14 16:04:21 +00:00
{
"id" : "CVE-2024-4854" ,
"sourceIdentifier" : "cve@gitlab.com" ,
"published" : "2024-05-14T15:45:18.890" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T09:43:44.263" ,
2024-05-14 18:03:25 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-05-14 16:04:21 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file"
2024-05-19 02:03:31 +00:00
} ,
{
"lang" : "es" ,
"value" : "Los bucles infinitos de disecci\u00f3n TLV de MONGO y ZigBee en Wireshark 4.2.0 a 4.2.4, 4.0.0 a 4.0.14 y 3.6.0 a 3.6.22 permiten la denegaci\u00f3n de servicio mediante inyecci\u00f3n de paquetes o archivo de captura manipulado"
2024-05-14 16:04:21 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.4 ,
"baseSeverity" : "MEDIUM" ,
2024-05-14 16:04:21 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-05-14 16:04:21 +00:00
} ,
"exploitabilityScore" : 1.6 ,
"impactScore" : 4.7
}
]
} ,
"weaknesses" : [
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-835"
}
]
}
] ,
"references" : [
{
"url" : "https://gitlab.com/wireshark/wireshark/-/issues/19726" ,
"source" : "cve@gitlab.com"
} ,
{
"url" : "https://gitlab.com/wireshark/wireshark/-/merge_requests/15047" ,
"source" : "cve@gitlab.com"
} ,
{
"url" : "https://gitlab.com/wireshark/wireshark/-/merge_requests/15499" ,
"source" : "cve@gitlab.com"
} ,
{
"url" : "https://www.wireshark.org/security/wnpa-sec-2024-07.html" ,
"source" : "cve@gitlab.com"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://gitlab.com/wireshark/wireshark/-/issues/19726" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://gitlab.com/wireshark/wireshark/-/merge_requests/15047" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://gitlab.com/wireshark/wireshark/-/merge_requests/15499" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://www.wireshark.org/security/wnpa-sec-2024-07.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-05-14 16:04:21 +00:00
}
]
}