CVE-2023-2858: Medium severity wireshark vulnerability
Published May 26, 2023
·Updated
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
Affected Software
5 affected componentsFixes available
debian/wireshark<=2.6.20-0+deb10u4, <=3.4.10-0+deb11u1
2.6.20-0+deb10u74.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.14
Wireshark Wireshark>=4.0.0<4.0.6
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Remediation
Patch Available
Event History
May 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-2858?
CVE-2023-2858 is a vulnerability in Wireshark versions 3.6.0 to 3.6.13 and 4.0.0 to 4.0.5 that allows denial of service through a crafted capture file.
2
How does CVE-2023-2858 affect Wireshark?
CVE-2023-2858 affects Wireshark versions 3.6.0 to 3.6.13 and 4.0.0 to 4.0.5, leading to a denial-of-service condition.
3
What is the severity of CVE-2023-2858?
CVE-2023-2858 has a severity rating of medium, with a CVSS score of 6.5.
4
How can I fix CVE-2023-2858?
To fix CVE-2023-2858, update Wireshark to version 3.6.14 or later for versions 3.6.x, and version 4.0.6 or later for versions 4.0.x.
5
Where can I find more information about CVE-2023-2858?
More information about CVE-2023-2858 can be found on the Wireshark website and the related GitLab issues.