PT-2023-16251 · Wireshark+3 · Wireshark+3

Published

2023-01-23

·

Updated

2024-09-30

·

CVE-2023-0413

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.6.0 through 3.6.10 Wireshark versions 4.0.0 through 4.0.2
Description The issue is related to a dissection engine bug in Wireshark, which allows for denial of service via packet injection or crafted capture file.
Recommendations For Wireshark versions 3.6.0 through 3.6.10, update to a version outside of this range to resolve the issue. For Wireshark versions 4.0.0 through 4.0.2, update to a version outside of this range to resolve the issue.

Exploit

Fix

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1113
ALT-PU-2023-1160
ALT-PU-2023-5823
ALT-PU-2023-6556
CVE-2023-0413
DLA-3313-1
DLA-3906-1
OESA-2023-1094
OESA-2023-1115
OPENSUSE-SU-2023_0343-1
OPENSUSE-SU-2024:12647-1
ROSA-SA-2023-2257
SUSE-SU-2023:0343-1

Affected Products

Alt Linux
Astra Linux
Suse
Wireshark