Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0666

Опубликовано: 18 мая 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

A flaw was found in the RTPS dissector of Wireshark. This issue occurs when decoding malformed packets from a pcap file or from the network, causing a buffer overflow, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkFixedRHSA-2023:701514.11.2023
Red Hat Enterprise Linux 9wiresharkFixedRHSA-2023:646907.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122

EPSS

Процентиль: 75%
0.00919
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVSS3: 6.5
nvd
около 2 лет назад

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVSS3: 6.5
debian
около 2 лет назад

Due to failure in validating the length provided by an attacker-crafte ...

CVSS3: 8.8
github
около 2 лет назад

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

oracle-oval
почти 2 года назад

ELSA-2023-7015: wireshark security update (MODERATE)

EPSS

Процентиль: 75%
0.00919
Низкий

6.5 Medium

CVSS3