PT-2023-16254 · Wireshark+3 · Wireshark+3

Published

2023-01-23

·

Updated

2024-09-30

·

CVE-2023-0416

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.6.0 through 3.6.10 Wireshark versions 4.0.0 through 4.0.2
Description The issue is related to a crash in the GNW dissector of Wireshark, which can be triggered by packet injection or a crafted capture file, leading to a denial of service.
Recommendations For Wireshark versions 3.6.0 through 3.6.10, update to a version outside of this range to resolve the issue. For Wireshark versions 4.0.0 through 4.0.2, update to a version outside of this range to resolve the issue.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1113
ALT-PU-2023-1160
ALT-PU-2023-5823
ALT-PU-2023-6556
CVE-2023-0416
DLA-3906-1
OESA-2023-1094
OESA-2023-1115
OPENSUSE-SU-2023_0343-1
OPENSUSE-SU-2024:12647-1
ROSA-SA-2023-2257
SUSE-SU-2023:0343-1

Affected Products

Alt Linux
Astra Linux
Suse
Wireshark