Release of Invalid Pointer or Reference
CVE-2024-2955
Summary
The component "T.38" dissector crash in wireshark package versions 4.0.0rc0 through 4.0.14rc0 and 4.2.0rc0 through 4.2.4rc0 allows Denial of Service via packet injection or crafted capture file.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-763 - Release of Invalid Pointer or Reference
The application attempts to return a memory resource to the system, but calls the wrong release function or calls the appropriate release function incorrectly.
References
Advisory Timeline
- Published