CVE-2023-0416: Medium severity wireshark vulnerability
GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0416?
CVE-2023-0416 is a vulnerability in Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 that allows denial of service through packet injection or a crafted capture file.
How severe is CVE-2023-0416?
CVE-2023-0416 has a severity value of 6.5, which is considered medium.
How does CVE-2023-0416 affect Wireshark?
CVE-2023-0416 affects Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10, potentially leading to a crash in the GNW dissector and causing denial of service.
What can an attacker do with CVE-2023-0416?
With CVE-2023-0416, an attacker can perform denial of service attacks by injecting malicious packets or using a specially-crafted capture file.
How can I fix CVE-2023-0416?
To fix CVE-2023-0416, it is recommended to update to a newer version of Wireshark that is not affected by the vulnerability.