First published: Wed Apr 12 2023(Updated: )
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=3.6.0<3.6.13 | |
Wireshark Wireshark | >=4.0.0<4.0.5 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =12.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
debian/wireshark | <=2.6.20-0+deb10u4<=3.4.10-0+deb11u1 | 2.6.20-0+deb10u7 4.0.6-1~deb12u1 4.0.10-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the LISP dissector large loop in Wireshark is CVE-2023-1993.
The severity of CVE-2023-1993 is medium, with a severity value of 6.5.
The LISP dissector large loop vulnerability in Wireshark allows denial of service attacks through packet injection or crafted capture files.
Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 are affected by CVE-2023-1993.
To fix the LISP dissector large loop vulnerability in Wireshark, update to Wireshark version 4.0.5 or later.