An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissectbgpopen(tvbufft*tvb, prototreetree, packet_infopinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
{
"isDisputed": true,
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24478.json",
"cna_assigner": "mitre"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.2.0"
}
],
"cpe": "cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.2.0"
}
],
"cpe": "cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE"
}"2026-06-16T07:00:00Z"
[
{
"digest": {
"line_hashes": [
"189510381883406169918325495416495645628",
"181089365518570185575899566930178211713",
"288824539015244219907814267140692011600",
"231711256843286469016356453456773215885",
"35100258221036831720984631592268922494",
"334244044918645183681682574178738743152",
"211445642022212795891193699352760917977",
"305277753338753293584358383658217787587",
"152452212672930070829047729190010841056",
"151113407929423182015904353390556114092",
"323156851194075810930943076740140246760"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2024-24478-2ea8e0eb",
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "epan/dissectors/packet-bgp.c"
},
"source": "https://github.com/wireshark/wireshark/commit/80a4dc55f4d2fa33c2b36a99406500726d3faaef"
},
{
"digest": {
"function_hash": "39544085995930972711160404121960114806",
"length": 152027.0
},
"signature_version": "v1",
"id": "CVE-2024-24478-8efb7f3e",
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "epan/dissectors/packet-bgp.c",
"function": "proto_register_bgp"
},
"source": "https://github.com/wireshark/wireshark/commit/80a4dc55f4d2fa33c2b36a99406500726d3faaef"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-24478.json"