PT-2023-16250 · Wireshark+3 · Wireshark+3

Published

2023-01-23

·

Updated

2024-09-30

·

CVE-2023-0412

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.6.0 through 3.6.10 Wireshark versions 4.0.0 through 4.0.2
Description The issue is related to a crash in the TIPC dissector of Wireshark, which can be triggered by packet injection or a crafted capture file, leading to a denial of service.
Recommendations For Wireshark versions 3.6.0 through 3.6.10, update to a version outside of this range to resolve the issue. For Wireshark versions 4.0.0 through 4.0.2, update to a version outside of this range to resolve the issue.

Exploit

Fix

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1113
ALT-PU-2023-1160
ALT-PU-2023-5823
ALT-PU-2023-6556
CVE-2023-0412
DLA-3313-1
DLA-3906-1
OESA-2023-1094
OESA-2023-1115
OPENSUSE-SU-2023_0343-1
OPENSUSE-SU-2024:12647-1
ROSA-SA-2023-2257
SUSE-SU-2023:0343-1

Affected Products

Alt Linux
Astra Linux
Suse
Wireshark