CVE-2024-4854

MEDIUM

Fedora < 3.6.22 - Infinite Loop

Title source: rule

Description

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file

Scores

CVSS v3 6.4
EPSS 0.0066
EPSS Percentile 70.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H

Classification

CWE
CWE-835
Status published

Affected Products (4)

fedoraproject/fedora
fedoraproject/fedora
wireshark/wireshark < 3.6.22
wireshark/wireshark < 4.2.4

Timeline

Published May 14, 2024
Tracked Since Feb 18, 2026