Lucene search

K
kasperskyKaspersky LabKLA62767
HistoryJan 03, 2024 - 12:00 a.m.

KLA62767 Multiple vulnerabilities in Wireshark

2024-01-0300:00:00
Kaspersky Lab
threats.kaspersky.com
16
wireshark
denial of service
vulnerabilities
update
exploits
cve-2024-0209
cve-2024-0208

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.8%

Multiple vulnerabilities were found in Wireshark. Malicious users can exploit these vulnerabilities to cause denial of service.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in IEEE 1609.2 and possibly other ASN.1-based dissectors can be exploited to cause denial of service.
  2. Denial of service vulnerability in GVCP dissector can be exploited to cause denial of service.

Original advisories

Wireshark • wnpa-sec-2024-02 IEEE 1609.2 dissector crash

Wireshark • wnpa-sec-2024-01 GVCP dissector crash

Exploitation

Public exploits exist for this vulnerability.

Related products

Wireshark

CVE list

CVE-2024-0209 warning

CVE-2024-0208 warning

Solution

Update to the latest version

Download Wireshark

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • Wireshark 3.6.x earlier than 3.6.20Wireshark 4.0.x earlier than 4.0.12Wireshark 4.2.x earlier than 4.2.1

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.8%