CVE-2024-8645
Moderate
Access of Uninitialized Pointer in Wireshark
SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file
Exploit probability
0.2%
Published
September 10, 2024
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
66 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2024-8645
View original source
SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8645.json
- https://gitlab.com/wireshark/wireshark/-/issues/19559
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-8645
- https://www.wireshark.org/security/wnpa-sec-2024-10.html