PT-2023-3430 · Wireshark+4 · Wireshark+4

Published

2023-04-12

·

Updated

2024-09-30

·

CVE-2023-1993

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.6.0 through 3.6.12 Wireshark versions 4.0.0 through 4.0.4
Description The issue is related to a large loop in the LISP dissector of Wireshark, which can lead to a denial of service via packet injection or crafted capture file. This can be exploited by a remote attacker to cause a service disruption.
Recommendations For Wireshark versions 3.6.0 through 3.6.12, update to a version that fixes this issue. For Wireshark versions 4.0.0 through 4.0.4, update to a version that fixes this issue. As a temporary workaround, consider disabling the LISP dissector until a patch is available.

Exploit

Fix

DoS

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1747
ALT-PU-2023-1771
ALT-PU-2023-5823
ALT-PU-2023-6556
BDU:2023-03347
BDU:2023-03609
CVE-2023-1993
DLA-3402-1
DLA-3906-1
DSA-5429-1
OESA-2023-1260
OESA-2023-1261
OPENSUSE-SU-2024:12865-1
ROSA-SA-2023-2257
ROSA-SA-2024-2388
SUSE-SU-2023:1931-1

Affected Products

Alt Linux
Astra Linux
Red Os
Suse
Wireshark