Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-2906

Опубликовано: 25 авг. 2023
Источник: debian

Описание

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wiresharkfixed4.0.8-1package
wiresharknot-affectedbusterpackage

Примечания

  • https://www.wireshark.org/security/wnpa-sec-2023-26.html

  • https://gitlab.com/wireshark/wireshark/-/issues/19229

  • Introduced by https://gitlab.com/wireshark/wireshark/-/commit/4ff777d5ce1d9951a1edbf7ffa914a12a00bb2b3 (v2.9.0)

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

CVSS3: 6.5
redhat
больше 2 лет назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

CVSS3: 6.5
nvd
больше 2 лет назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 6.5
github
больше 2 лет назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.