CVE-2023-1993: Medium severity wireshark vulnerability
Published Apr 12, 2023
·Updated
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Affected Software
8 affected componentsFixes available
debian/wireshark<=2.6.20-0+deb10u4, <=3.4.10-0+deb11u1
2.6.20-0+deb10u74.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.13
Wireshark Wireshark>=4.0.0<4.0.5
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Remediation
Patch Available
Event History
Apr 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the LISP dissector large loop in Wireshark?
The vulnerability ID for the LISP dissector large loop in Wireshark is CVE-2023-1993.
2
What is the severity of CVE-2023-1993?
The severity of CVE-2023-1993 is medium, with a severity value of 6.5.
3
How does the LISP dissector large loop vulnerability in Wireshark allow denial of service attacks?
The LISP dissector large loop vulnerability in Wireshark allows denial of service attacks through packet injection or crafted capture files.
4
Which versions of Wireshark are affected by CVE-2023-1993?
Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 are affected by CVE-2023-1993.
5
How can I fix the LISP dissector large loop vulnerability in Wireshark?
To fix the LISP dissector large loop vulnerability in Wireshark, update to Wireshark version 4.0.5 or later.