CVE-2023-0412: High severity wireshark vulnerability
TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0412?
CVE-2023-0412 is a vulnerability in Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 that allows denial of service via packet injection or crafted capture file.
How does CVE-2023-0412 affect Wireshark?
CVE-2023-0412 affects Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 by causing a crash in the TIPC dissector, leading to denial of service.
What software is affected by CVE-2023-0412?
Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 as well as Debian Linux version 10.0 are affected by CVE-2023-0412.
How severe is CVE-2023-0412?
CVE-2023-0412 has a severity score of 7.1, which is classified as high.
How can I fix CVE-2023-0412?
To fix CVE-2023-0412, update Wireshark to version 4.0.3 or higher or 3.6.11 or higher. For Debian Linux, update to the latest available package.