CVE-2024-9780Missing Initialization of a Variable in Foundation Wireshark

Severity
5.5MEDIUMNVD
CNA7.8
EPSS
0.1%
top 78.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10

Description

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5wireshark_foundation/wireshark4.4.04.4.1
Debianwireshark/wireshark< 4.4.1-1+1

🔴Vulnerability Details

3
CVEList
Missing Initialization of a Variable in Wireshark2024-10-10
GHSA
GHSA-4rf2-7phj-4vwq: ITS dissector crash in Wireshark 42024-10-10
OSV
CVE-2024-9780: ITS dissector crash in Wireshark 42024-10-10

💥Exploits & PoCs

1
Nuclei
Cluster Control CMON API - Directory Traversal

📋Vendor Advisories

1
Debian
CVE-2024-9780: wireshark - ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injec...2024
CVE-2024-9780 — Missing Initialization of a Variable | cvebase