CVE-2023-0413: Null Pointer Dereference
Published Jan 24, 2023
·Updated
Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Affected Software
2 affected components
Wireshark Wireshark>=3.6.0<=3.6.10
Wireshark Wireshark>=4.0.0<=4.0.2
Remediation
Patch Available
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jan 26, 2023
Data Sourced
via NVD·09:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Wireshark bug?
The vulnerability ID for this Wireshark bug is CVE-2023-0413.
2
What is the affected version range of Wireshark?
The affected version range of Wireshark is 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10.
3
How can this vulnerability be exploited?
This vulnerability can be exploited through packet injection or a crafted capture file, leading to denial of service.
4
What is the severity of CVE-2023-0413?
The severity of CVE-2023-0413 is medium.
5
Is there a fix available for this vulnerability?
Yes, updates have been released to address this vulnerability. It is recommended to update to the latest version of Wireshark.