CVE-2023-2879: High severity wireshark vulnerability
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this Wireshark issue?
The vulnerability ID of this Wireshark issue is CVE-2023-2879.
What is the severity of CVE-2023-2879?
The severity of CVE-2023-2879 is high (7 out of 10).
How does CVE-2023-2879 affect the Wireshark software?
CVE-2023-2879 allows denial of service through packet injection or crafted capture file in Wireshark versions 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13.
How can I fix CVE-2023-2879 in Wireshark?
To fix CVE-2023-2879 in Wireshark, update to versions 3.6.14 or later for 3.x branch, and versions 4.0.6 or later for 4.x branch.
Where can I find more information about CVE-2023-2879?
You can find more information about CVE-2023-2879 at the following references: 1. [Issue on GitLab](https://gitlab.com/wireshark/wireshark/-/issues/19068) 2. [CVE JSON](https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2879.json) 3. [Wireshark Security Advisory](https://www.wireshark.org/security/wnpa-sec-2023-14.html)