CVE-2024-8250
High
Expired Pointer Dereference in Wireshark
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
Exploit probability
0.3%
Published
August 28, 2024
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
72 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2024-8250
View original source
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8250.json
- https://gitlab.com/wireshark/wireshark/-/issues/19943
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-8250
- https://www.wireshark.org/security/wnpa-sec-2024-11.html