Lucene search

K
cveGitLabCVE-2024-4855
HistoryMay 14, 2024 - 3:45 p.m.

CVE-2024-4855

2024-05-1415:45:19
CWE-416
GitLab
web.nvd.nist.gov
15
cve-2024-4855
nvd
crafted capture file

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

AI Score

5.3

Confidence

High

EPSS

0

Percentile

16.3%

Use after free issue in editcap could cause denial of service via crafted capture file

Affected configurations

Vulners
Node
wireshark_foundationeditcapRange4.2.04.2.5
OR
wireshark_foundationeditcapRange4.0.04.0.15
OR
wireshark_foundationeditcapRange3.6.03.6.23
VendorProductVersionCPE
wireshark_foundationeditcap*cpe:2.3:a:wireshark_foundation:editcap:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "editcap",
    "vendor": "Wireshark Foundation",
    "versions": [
      {
        "lessThan": "4.2.5",
        "status": "affected",
        "version": "4.2.0",
        "versionType": "semver"
      },
      {
        "lessThan": "4.0.15",
        "status": "affected",
        "version": "4.0.0",
        "versionType": "semver"
      },
      {
        "lessThan": "3.6.23",
        "status": "affected",
        "version": "3.6.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

3.6

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

AI Score

5.3

Confidence

High

EPSS

0

Percentile

16.3%