CVE-2023-2854
published 2023-05-26CVE-2023-2854: BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.88%
54.9th percentile
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 4.0.6-1~deb12u1 (bookworm) | wireshark 4.0.6-1~deb12u1 (bookworm) |
| wireshark | wireshark | >= 0 < 4.0.6-1~deb12u1 | 4.0.6-1~deb12u1 |
| wireshark | wireshark | >= 0 < 4.0.6-1 | 4.0.6-1 |
| wireshark | wireshark | >= 0 < 4.0.6-1 | 4.0.6-1 |
| wireshark | wireshark | >= 3.6.0 < 3.6.14 | 3.6.14 |
| wireshark | wireshark | >= 4.0.0 < 4.0.6 | 4.0.6 |
| wireshark_foundation | wireshark | — | — |
| wireshark_foundation | wireshark | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: BLF file parser crash
vendor_redhat·2023-05-18·CVSS 5.3
CVE-2023-2854 [MEDIUM] CWE-126 wireshark: BLF file parser crash
wireshark: BLF file parser crash
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
A flaw was found in the BLF file parser of Wireshark. This issue occurs when decoding malformed packets from a PCAP file or the network, causing a buffer over-read, which results in a denial of service.
Statement: Wireshark, as shipped in Red Hat Enterprise Linux 8 and 9, is not affected by this vulnerability because the BLF file parser was introduced in a newer Wireshark version.
Package: wireshark (Red Hat Enterprise Linux 6) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 7) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 8) - Not affected
Package: wireshark (Red Hat Enterprise Linux 9) - N
Debian
CVE-2023-2854: wireshark - BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows den...
vendor_debian·2023·CVSS 5.3
CVE-2023-2854 [MEDIUM] CVE-2023-2854: wireshark - BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows den...
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.6-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 4.0.6-1)
sid: resolved (fixed in 4.0.6-1)
trixie: resolved (fixed in 4.0.6-1)
GHSA
GHSA-wf7c-7cm2-c3g5: BLF file parser crash in Wireshark 4
ghsa_unreviewed·2023-05-26
CVE-2023-2854 [MEDIUM] CWE-787 GHSA-wf7c-7cm2-c3g5: BLF file parser crash in Wireshark 4
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
OSV
CVE-2023-2854: BLF file parser crash in Wireshark 4
osv·2023-05-26·CVSS 6.5
CVE-2023-2854 [MEDIUM] CVE-2023-2854: BLF file parser crash in Wireshark 4
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
No detection rules found.
No public exploits indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2854.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/19084https://security.gentoo.org/glsa/202309-02https://www.debian.org/security/2023/dsa-5429https://www.wireshark.org/security/wnpa-sec-2023-17.htmlhttps://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2854.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/19084https://security.gentoo.org/glsa/202309-02https://www.debian.org/security/2023/dsa-5429https://www.wireshark.org/security/wnpa-sec-2023-17.html
2023-05-26
Published