CVE-2023-5371
published 2023-10-04CVE-2023-5371: RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
PriorityP425medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.48%
38.6th percentile
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.0.11-1~deb12u1 (bookworm) | wireshark 4.0.11-1~deb12u1 (bookworm) |
| gitlab | wireshark | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| wireshark | wireshark | >= 0 < 4.0.11-1~deb12u1 | 4.0.11-1~deb12u1 |
| wireshark | wireshark | >= 0 < 4.0.10-1 | 4.0.10-1 |
| wireshark | wireshark | >= 0 < 4.0.10-1 | 4.0.10-1 |
| wireshark | wireshark | >= 3.6.0 < 3.6.17 | 3.6.17 |
| wireshark | wireshark | >= 4.0.0 < 4.0.9 | 4.0.9 |
| wireshark_foundation | wireshark | >= 3.6.0 < 3.6.17 | 3.6.17 |
| wireshark_foundation | wireshark | >= 4.0.0 < 4.0.9 | 4.0.9 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-5371: RTPS dissector memory leak in Wireshark 4
osv·2023-10-04·CVSS 6.5
CVE-2023-5371 [MEDIUM] CVE-2023-5371: RTPS dissector memory leak in Wireshark 4
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
GHSA
GHSA-j7xf-pgw2-75mr: RTPS dissector memory leak in Wireshark 4
ghsa_unreviewed·2023-10-04
CVE-2023-5371 [MEDIUM] CWE-770 GHSA-j7xf-pgw2-75mr: RTPS dissector memory leak in Wireshark 4
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
Microsoft
Memory Allocation with Excessive Size Value in Wireshark
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-5371 [MEDIUM] CWE-789 Memory Allocation with Excessive Size Value in Wireshark
Memory Allocation with Excessive Size Value in Wireshark
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2023-5371
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitLab: GitLab
Customer Action Requi
Red Hat
wireshark: RTPS dissector memory leak
vendor_redhat·2023-10-04·CVSS 5.3
CVE-2023-5371 [MEDIUM] CWE-401 wireshark: RTPS dissector memory leak
wireshark: RTPS dissector memory leak
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
A memory leak flaw was found in Wireshark's RTPS dissector. This issue may cause an application crash via packet injection or crafted capture file.
Statement: Default memory protections in Red Hat Enterprise Linux should prevent this issue from causing a higher impact than an application crash in the user context. Therefore, the severity of this flaw is low.
Package: wireshark (Red Hat Enterprise Linux 6) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 7) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 8) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux
GitLab
Memory Allocation with Excessive Size Value in Wireshark
vendor_gitlab·2023-10-04·CVSS 6.5
CVE-2023-5371 [MEDIUM] CWE-789 Memory Allocation with Excessive Size Value in Wireshark
Memory Allocation with Excessive Size Value in Wireshark
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
Affected products: Wireshark
Affected versions: >=4.0.0, =3.6.0, <3.6.17 (affected)
Solution: Upgrade to version 4.0.9, 3.6.17 or above.
Debian
CVE-2023-5371: wireshark - RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allow...
vendor_debian·2023·CVSS 5.3
CVE-2023-5371 [MEDIUM] CVE-2023-5371: wireshark - RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allow...
RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: resolved (fixed in 4.0.11-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 4.0.10-1)
sid: resolved (fixed in 4.0.10-1)
trixie: resolved (fixed in 4.0.10-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/wireshark/wireshark/-/issues/19322https://www.wireshark.org/security/wnpa-sec-2023-27.htmlhttps://gitlab.com/wireshark/wireshark/-/issues/19322https://lists.fedoraproject.org/archives/list/[email protected]/message/34DBP5P2RHQ7XUABPANYYMOGV5KS6VEP/https://lists.fedoraproject.org/archives/list/[email protected]/message/MADSCHKZSCKQ5NLIX3UMOIJD2JZ65L4V/https://security.gentoo.org/glsa/202402-09https://www.wireshark.org/security/wnpa-sec-2023-27.html
2023-10-04
Published