First published: Wed Apr 12 2023(Updated: )
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=3.6.0<3.6.13 | |
Wireshark Wireshark | >=4.0.0<4.0.5 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =12.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
debian/wireshark | <=2.6.20-0+deb10u4<=3.4.10-0+deb11u1 | 2.6.20-0+deb10u7 4.0.6-1~deb12u1 4.0.10-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1992 is a vulnerability in Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 that allows denial of service through packet injection or crafted capture file.
This vulnerability can be exploited through packet injection or by using a crafted capture file.
CVE-2023-1992 has a severity level of high with a CVSS score of 7.5.
Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 are affected by this vulnerability.
To fix CVE-2023-1992, update your Wireshark software to version 4.0.5 or later.