CVE-2023-1992: High severity wireshark vulnerability
Published Apr 12, 2023
·Updated
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Affected Software
8 affected componentsFixes available
debian/wireshark<=2.6.20-0+deb10u4, <=3.4.10-0+deb11u1
2.6.20-0+deb10u74.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.13
Wireshark Wireshark>=4.0.0<4.0.5
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Remediation
Patch Available
Event History
Apr 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-1992?
CVE-2023-1992 is a vulnerability in Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 that allows denial of service through packet injection or crafted capture file.
2
How can this vulnerability be exploited?
This vulnerability can be exploited through packet injection or by using a crafted capture file.
3
What is the severity level of CVE-2023-1992?
CVE-2023-1992 has a severity level of high with a CVSS score of 7.5.
4
Which software versions are affected by this vulnerability?
Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 are affected by this vulnerability.
5
How can I fix CVE-2023-1992?
To fix CVE-2023-1992, update your Wireshark software to version 4.0.5 or later.