CVE-2024-9780
published 2024-10-10CVE-2024-9780: ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.25%
15.9th percentile
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.4.1-1 (forky) | wireshark 4.4.1-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.4.1-1 | 4.4.1-1 |
| wireshark | wireshark | >= 0 < 4.4.1-1 | 4.4.1-1 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.1 | 4.4.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Missing Initialization of a Variable in Wireshark
vendor_gitlab·2024-10-10·CVSS 5.5
CVE-2024-9780 [MEDIUM] CWE-456 Missing Initialization of a Variable in Wireshark
Missing Initialization of a Variable in Wireshark
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
Affected products: Wireshark
Affected versions: >=4.4.0, <4.4.1 (affected)
Solution: Upgrade to version 4.4.1 or above.
Debian
CVE-2024-9780: wireshark - ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injec...
vendor_debian·2024·CVSS 7.8
CVE-2024-9780 [HIGH] CVE-2024-9780: wireshark - ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injec...
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed in 4.4.1-1)
trixie: resolved (fixed in 4.4.1-1)
GHSA
GHSA-4rf2-7phj-4vwq: ITS dissector crash in Wireshark 4
ghsa_unreviewed·2024-10-10
CVE-2024-9780 [HIGH] CWE-456 GHSA-4rf2-7phj-4vwq: ITS dissector crash in Wireshark 4
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
OSV
CVE-2024-9780: ITS dissector crash in Wireshark 4
osv·2024-10-10·CVSS 5.5
CVE-2024-9780 [MEDIUM] CVE-2024-9780: ITS dissector crash in Wireshark 4
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
No detection rules found.
Nuclei
Cluster Control CMON API - Directory Traversal
nuclei·CVSS 7.5
CVE-2024-41628 [HIGH] Cluster Control CMON API - Directory Traversal
Cluster Control CMON API - Directory Traversal
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.
Template:
id: CVE-2024-41628
info:
name: Cluster Control CMON API - Directory Traversal
author: s4e-io
severity: high
description: |
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.
impact: |
Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Cluster Control server.
remedia
No writeups or analysis indexed.
2024-10-10
Published