CVE-2023-2952: Medium severity wireshark vulnerability
Published May 30, 2023
·Updated
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
Affected Software
5 affected componentsFixes available
debian/wireshark<=2.6.20-0+deb10u4, <=3.4.10-0+deb11u1
2.6.20-0+deb10u74.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.6.0<3.6.14
Wireshark Wireshark>=4.0.0<4.0.6
Debian Debian Linux=10.0
Debian Debian Linux=12.0
Event History
May 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
11:15 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Wireshark issue?
The vulnerability ID is CVE-2023-2952.
2
What is the severity rating of CVE-2023-2952?
The severity rating of CVE-2023-2952 is medium (6.5).
3
Which versions of Wireshark are affected by CVE-2023-2952?
Wireshark versions 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 are affected.
4
How can an attacker exploit CVE-2023-2952?
An attacker can exploit CVE-2023-2952 by performing packet injection or using a crafted capture file.
5
How can I fix the CVE-2023-2952 vulnerability in Wireshark?
To fix the CVE-2023-2952 vulnerability, update Wireshark to version 4.0.6 or later.