CVE-2023-2856: Medium severity wireshark vulnerability
Published May 26, 2023
·Updated
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
Affected Software
5 affected componentsFixes available
debian/wireshark<=2.6.20-0+deb10u4, <=3.4.10-0+deb11u1
2.6.20-0+deb10u74.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.14
Wireshark Wireshark>=4.0.0<4.0.6
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Remediation
Patch Available
Event History
May 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Wireshark vulnerability?
The vulnerability ID for this Wireshark vulnerability is CVE-2023-2856.
2
What is the severity of CVE-2023-2856?
The severity of CVE-2023-2856 is medium (CVSS score: 6.5).
3
Which versions of Wireshark are affected by this vulnerability?
This vulnerability affects Wireshark versions 3.6.0 to 3.6.13 and 4.0.0 to 4.0.5.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by crafting a malicious capture file, which can lead to a denial of service.
5
Is there a fix available for CVE-2023-2856?
Yes, a fix is available. It is recommended to upgrade to the patched versions: 3.6.14 or later for Wireshark 3.6.x, and 4.0.6 or later for Wireshark 4.0.x.