CVE-2024-11596
published 2024-11-21CVE-2024-11596: ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.30%
22.1th percentile
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.2-1 | 4.4.2-1 |
| wireshark | wireshark | >= 0 < 4.4.2-1 | 4.4.2-1 |
| wireshark | wireshark | >= 4.2.0 < 4.2.9 | 4.2.9 |
| wireshark | wireshark | >= 4.4.0 < 4.4.2 | 4.4.2 |
| wireshark_foundation | wireshark | >= 4.2.0 < 4.2.9 | 4.2.9 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.2 | 4.4.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Buffer Over-read in Wireshark
vendor_redhat·2024-11-21·CVSS 7.8
CVE-2024-11596 [HIGH] CWE-126 wireshark: Buffer Over-read in Wireshark
wireshark: Buffer Over-read in Wireshark
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
A flaw was found in Wireshark's ECMP dissector. This issue occurs when malformed packets are decoded from a pcap file or the network, causing a buffer over-read and resulting in a denial of service.
Statement: This vulnerability will cause a crash in Wireshark with no other security impact. For this reason, this flaw has been rated with a moderate severity.
Mitigation: If the ECMP protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using "tshark", the command line tool.
See the links
GitLab
Buffer Over-read in Wireshark
vendor_gitlab·2024-11-21·CVSS 5.5
CVE-2024-11596 [MEDIUM] CWE-126 Buffer Over-read in Wireshark
Buffer Over-read in Wireshark
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
Affected products: Wireshark
Affected versions: >=4.4.0, =4.2.0, <4.2.9 (affected)
Solution: Upgrade to version 4.4.2, 4.2.9 or above.
Credit: Ivan Nardi
Debian
CVE-2024-11596: wireshark - ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denia...
vendor_debian·2024·CVSS 7.8
CVE-2024-11596 [HIGH] CVE-2024-11596: wireshark - ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denia...
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.4.2-1)
sid: resolved (fixed in 4.4.2-1)
trixie: resolved (fixed in 4.4.2-1)
GHSA
GHSA-pm69-rqj8-f5fq: ECMP dissector crash in Wireshark 4
ghsa_unreviewed·2025-05-07
CVE-2024-11596 [MEDIUM] CWE-125 GHSA-pm69-rqj8-f5fq: ECMP dissector crash in Wireshark 4
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
OSV
CVE-2024-11596: ECMP dissector crash in Wireshark 4
osv·2024-11-21·CVSS 5.5
CVE-2024-11596 [MEDIUM] CVE-2024-11596: ECMP dissector crash in Wireshark 4
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-21
Published