CVE-2023-1994: Null Pointer Dereference
Published Apr 12, 2023
·Updated
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Affected Software
8 affected componentsFixes available
debian/wireshark<=2.6.20-0+deb10u4, <=3.4.10-0+deb11u1
2.6.20-0+deb10u74.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.13
Wireshark Wireshark>=4.0.0<4.0.5
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Event History
Apr 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-1994?
The severity of CVE-2023-1994 is medium with a CVSS score of 6.5.
2
Which versions of Wireshark are affected by CVE-2023-1994?
Wireshark versions 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 are affected by CVE-2023-1994.
3
How can CVE-2023-1994 be exploited?
CVE-2023-1994 can be exploited through packet injection or crafted capture file.
4
Is there a fix available for CVE-2023-1994?
Yes, fixes are available. Wireshark version 4.0.5 and above, and Debian package versions 2.6.20-0+deb10u7, 4.0.6-1~deb12u1, and 4.0.8-1 include the fixes.
5
Where can I find more information about CVE-2023-1994?
You can find more information about CVE-2023-1994 in the references provided: [link1], [link2], [link3].