CVE-2024-4854

M

ONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:*:-:*:*:*:*:*:*

History

03 Nov 2025, 23:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html -

18 Apr 2025, 16:34

Type Values Removed Values Added
CPE cpe:2.3:a:wireshark:wireshark:*:-:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
References () https://gitlab.com/wireshark/wireshark/-/issues/19726 - () https://gitlab.com/wireshark/wireshark/-/issues/19726 - Issue Tracking
References () https://gitlab.com/wireshark/wireshark/-/merge_requests/15047 - () https://gitlab.com/wireshark/wireshark/-/merge_requests/15047 - Product
References () https://gitlab.com/wireshark/wireshark/-/merge_requests/15499 - () https://gitlab.com/wireshark/wireshark/-/merge_requests/15499 - Product
References () https://www.wireshark.org/security/wnpa-sec-2024-07.html - () https://www.wireshark.org/security/wnpa-sec-2024-07.html - Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/[email protected]/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/ - () https://lists.fedoraproject.org/archives/list/[email protected]/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/ - Mailing List
References () https://lists.fedoraproject.org/archives/list/[email protected]/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/ - () https://lists.fedoraproject.org/archives/list/[email protected]/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/ - Mailing List
First Time Wireshark wireshark
Wireshark
Fedoraproject fedora
Fedoraproject

21 Nov 2024, 09:43

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/ -
References () https://gitlab.com/wireshark/wireshark/-/issues/19726 - () https://gitlab.com/wireshark/wireshark/-/issues/19726 -
References () https://gitlab.com/wireshark/wireshark/-/merge_requests/15047 - () https://gitlab.com/wireshark/wireshark/-/merge_requests/15047 -
References () https://gitlab.com/wireshark/wireshark/-/merge_requests/15499 - () https://gitlab.com/wireshark/wireshark/-/merge_requests/15499 -
References () https://www.wireshark.org/security/wnpa-sec-2024-07.html - () https://www.wireshark.org/security/wnpa-sec-2024-07.html -

29 Aug 2024, 15:15

Type Values Removed Values Added
References

10 Jun 2024, 18:15

Type Values Removed Values Added
Summary
  • (es) Los bucles infinitos de disección TLV de MONGO y ZigBee en Wireshark 4.2.0 a 4.2.4, 4.0.0 a 4.0.14 y 3.6.0 a 3.6.22 permiten la denegación de servicio mediante inyección de paquetes o archivo de captura manipulado
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/66H2BSENPSIALF2WIZF7M3QBVWYBMFGW/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/7MKFJAZDKXGFFQPRDYLX2AANRNMYZZEZ/ -

14 May 2024, 15:45

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:45

Updated : 2025-11-03 23:16


NVD link : CVE-2024-4854

Mitre link : CVE-2024-4854

CVE.ORG link : CVE-2024-4854


JSON object : View

CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')