CVE-2023-3649Buffer Over-read in Foundation Wireshark

Severity
5.5MEDIUMNVD
CNA5.3
EPSS
0.0%
top 92.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14

Description

iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5wireshark_foundation/wireshark4.0.04.0.7
Debianwireshark/wireshark< 3.4.16-0+deb11u1+3
NVDwireshark/wireshark4.0.04.0.6

🔴Vulnerability Details

3
CVEList
Buffer Over-read in Wireshark2023-07-14
OSV
CVE-2023-3649: iSCSI dissector crash in Wireshark 42023-07-14
GHSA
GHSA-cfcv-vwxf-fg7x: iSCSI dissector crash in Wireshark 42023-07-14

📋Vendor Advisories

1
Debian
CVE-2023-3649: wireshark - iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via p...2023
CVE-2023-3649 — Buffer Over-read | cvebase