CVE-2023-0411Excessive Iteration in Wireshark

Severity
6.5MEDIUMNVD
CNA6.3
EPSS
0.1%
top 74.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26
Latest updateJan 27

Description

Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

Debianwireshark/wireshark< 3.4.16-0+deb11u1+3
NVDwireshark/wireshark3.6.03.6.10+1
CVEListV5wireshark_foundation/wireshark>=3.6.0, <3.6.11, >=4.0.0, <4.0.3+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q67r-2p55-6v2v: Excessive loops in multiple dissectors in Wireshark 42023-01-26
OSV
CVE-2023-0411: Excessive loops in multiple dissectors in Wireshark 42023-01-26
CVEList
CVE-2023-0411: Excessive loops in multiple dissectors in Wireshark 42023-01-24

📋Vendor Advisories

2
Red Hat
wireshark: Multiple dissector excessive loops2023-01-27
Debian
CVE-2023-0411: wireshark - Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to ...2023
CVE-2023-0411 — Excessive Iteration in Wireshark | cvebase