CVE-2023-0415: Null Pointer Dereference
Published Jan 24, 2023
·Updated
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Affected Software
2 affected components
Wireshark Wireshark>=3.6.0<=3.6.10
Wireshark Wireshark>=4.0.0<=4.0.2
Remediation
Patch Available
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Jan 26, 2023
Data Sourced
via NVD·09:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this iSCSI dissector crash?
The vulnerability ID of this iSCSI dissector crash is CVE-2023-0415.
2
In which versions of Wireshark does this vulnerability exist?
This vulnerability exists in Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10.
3
What is the impact of this vulnerability?
This vulnerability allows denial of service via packet injection or crafted capture file.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by injecting malicious packets or using a crafted capture file.
5
Are there any fixes available for this vulnerability?
Yes, fixes for this vulnerability are available. Please refer to the references for more information.