CVE-2024-24479

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
21/02/2024
Last modified:
04/11/2025

Description

A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* 4.2.0 (excluding)
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*