Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9 MGASA-2024-0303: Critical Wireshark NTLMSSP Threat

mageia
Calendar Grey September 16, 2024
Dist Mageia Esm H88
Mageia releases an update for Wireshark to address a critical vulnerability in the NTLMSSP dissector, disclosed on 16 Sep 2024.
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.2.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

Summary

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.2.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file. (CVE-2024-8250)

References

- https://bugs.mageia.org/show_bug.cgi?id=33558

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QKFBRZUBCTYT4V2V5ONIWBIEEUYHI3HD/

- https://www.cve.org/CVERecord?id=CVE-2024-8250

Resolution

SRPMS

- 9/core/wireshark-4.0.17-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 16 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0303.html
Type: security
CVE: CVE-2024-8250

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here