CVE-2024-4855Use After Free in Foundation Editcap

CWE-416Use After Free7 documents7 sources
Severity
5.5MEDIUMNVD
CNA3.6
EPSS
0.0%
top 93.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

Use after free issue in editcap could cause denial of service via crafted capture file

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5wireshark_foundation/editcap4.2.04.2.5+2
NVDwireshark/wireshark3.6.03.6.23+2
Debianwireshark/wireshark< 4.0.17-0+deb12u1+2

Also affects: Fedora 39, 40

🔴Vulnerability Details

3
OSV
CVE-2024-4855: Use after free issue in editcap could cause denial of service via crafted capture file2024-05-14
CVEList
Use After Free in editcap2024-05-14
GHSA
GHSA-9g56-qqc5-7rw9: Use after free issue in editcap could cause denial of service via crafted capture file2024-05-14

📋Vendor Advisories

3
Microsoft
Use After Free in editcap2024-05-14
Red Hat
wireshark: Editcap secret injection crash2024-05-14
Debian
CVE-2024-4855: wireshark - Use after free issue in editcap could cause denial of service via crafted captur...2024
CVE-2024-4855 — Use After Free in Foundation Editcap | cvebase