CVE-2024-9781
published 2024-10-10CVE-2024-9781: AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
22.6th percentile
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.1-1 | 4.4.1-1 |
| wireshark | wireshark | >= 0 < 4.4.1-1 | 4.4.1-1 |
| wireshark | wireshark | >= 4.2.0 < 4.2.8 | 4.2.8 |
| wireshark_foundation | wireshark | >= 4.2.0 < 4.2.8 | 4.2.8 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.1 | 4.4.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-9781: AppleTalk and RELOAD Framing dissector crash in Wireshark 4
osv·2024-10-10·CVSS 7.5
CVE-2024-9781 [HIGH] CVE-2024-9781: AppleTalk and RELOAD Framing dissector crash in Wireshark 4
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
GHSA
GHSA-752v-9q7h-jp65: AppleTalk and RELOAD Framing dissector crash in Wireshark 4
ghsa_unreviewed·2024-10-10
CVE-2024-9781 [HIGH] CWE-230 GHSA-752v-9q7h-jp65: AppleTalk and RELOAD Framing dissector crash in Wireshark 4
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
GitLab
Improper Handling of Missing Values in Wireshark
vendor_gitlab·2024-10-10·CVSS 7.5
CVE-2024-9781 [HIGH] CWE-230 Improper Handling of Missing Values in Wireshark
Improper Handling of Missing Values in Wireshark
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
Affected products: Wireshark
Affected versions: >=4.4.0, =4.2.0, <4.2.8 (affected)
Solution: Upgrade to version 4.4.1, 4.2.8 or above.
Red Hat
wireshark: Improper Handling of Missing Values in Wireshark
vendor_redhat·2024-10-10·CVSS 7.8
CVE-2024-9781 [HIGH] CWE-230 wireshark: Improper Handling of Missing Values in Wireshark
wireshark: Improper Handling of Missing Values in Wireshark
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
A flaw was found in the AppleTalk and RELOAD Framing dissectors of Wireshark. This issue occurs when decoding malformed packets from a pcap file or from the network, causing an invalid read memory access and a denial of service.
Statement: This vulnerability will cause a crash in Wireshark with no other security impact. For this reason, this flaw has been rated with a moderate severity.
Additionally, Wireshark as shipped in Red Hat Enterprise Linux 8 and 9 is not affected by this vulnerability.
Mitigation: If the AppleTalk and RELOAD Framing protocol dissectors are not being u
Debian
CVE-2024-9781: wireshark - AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2...
vendor_debian·2024·CVSS 7.8
CVE-2024-9781 [HIGH] CVE-2024-9781: wireshark - AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2...
AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.4.1-1)
sid: resolved (fixed in 4.4.1-1)
trixie: resolved (fixed in 4.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-10
Published