CVE-2023-3649: Buffer Over-read in Wireshark
Published Jul 14, 2023
·Updated
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
Affected Software
1 affected component
Wireshark Wireshark>=4.0.0<=4.0.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.0.7
Event History
Jul 14, 2023
CVE Published
via MITRE·06:16 AM
Data Sourced
via MITRE·06:16 AM
RemedyDescriptionSeverityWeakness
Data Sourced
07:15 AM
Description
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for iSCSI dissector crash in Wireshark?
The vulnerability ID for the iSCSI dissector crash in Wireshark is CVE-2023-3649.
2
What is the severity of CVE-2023-3649?
CVE-2023-3649 has a severity level of medium.
3
How does the iSCSI dissector crash vulnerability in Wireshark affect the software?
The iSCSI dissector crash vulnerability affects Wireshark versions 4.0.0 to 4.0.6.
4
How can an attacker exploit CVE-2023-3649?
An attacker can exploit CVE-2023-3649 by performing packet injection or using a crafted capture file.
5
Is there a fix available for the iSCSI dissector crash vulnerability in Wireshark?
Yes, you can refer to the official Wireshark website or the provided GitLab issue for information on available fixes.