Uncontrolled Recursion in Wireshark
CVE-2024-0210

7.8HIGH

Key Information:

Vendor
Wireshark
Status
Vendor
CVE Published:
3 January 2024

Summary

A vulnerability exists in the Wireshark application within the Zigbee TLV dissector, specifically in version 4.2.0. Attackers can exploit this vulnerability to cause a denial of service condition by injecting malicious packets or using specially crafted capture files. This may result in unexpected application crashes, impacting the availability of the service for legitimate users. Proper input validation measures should be implemented to prevent such scenarios.

Affected Version(s)

Wireshark 4.2.0 < 4.2.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Han Zheng
.