rpm package
suse/wireshark&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4
pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-24476 | — | < 3.6.22-150000.3.112.1 | 3.6.22-150000.3.112.1 | Feb 21, 2024 | A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | ||
| CVE-2024-0209 | — | < 3.6.20-150000.3.109.1 | 3.6.20-150000.3.109.1 | Jan 3, 2024 | IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file | ||
| CVE-2024-0208 | — | < 3.6.20-150000.3.109.1 | 3.6.20-150000.3.109.1 | Jan 3, 2024 | GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file |
- CVE-2024-24476Feb 21, 2024affected < 3.6.22-150000.3.112.1fixed 3.6.22-150000.3.112.1
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
- CVE-2024-0209Jan 3, 2024affected < 3.6.20-150000.3.109.1fixed 3.6.20-150000.3.109.1
IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file
- CVE-2024-0208Jan 3, 2024affected < 3.6.20-150000.3.109.1fixed 3.6.20-150000.3.109.1
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file