CVE-2023-2857: Medium severity wireshark vulnerability
Published May 26, 2023
·Updated
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
Affected Software
4 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.14
Wireshark Wireshark>=4.0.0<4.0.6
Debian Debian Linux=12.0
Remediation
Patch Available
Event History
May 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-2857?
CVE-2023-2857 is a vulnerability in Wireshark versions 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 that allows denial of service through a crafted capture file.
2
What is the severity of CVE-2023-2857?
The severity of CVE-2023-2857 is medium, with a CVSS score of 6.5.
3
How can CVE-2023-2857 be exploited?
CVE-2023-2857 can be exploited by an attacker using a specially crafted BLF file that triggers a crash in the Wireshark file parser.
4
Which versions of Wireshark are affected by CVE-2023-2857?
Wireshark versions 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 are affected by CVE-2023-2857.
5
What is the recommended remedy for CVE-2023-2857?
The recommended remedy for CVE-2023-2857 is to update Wireshark to version 4.0.6 or later.