Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1161

Опубликовано: 04 мар. 2023
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file

A flaw was found in the ISO 15765 and ISO 10681 dissectors of Wireshark. This issue occurs when decoding malformed packets from a pcap file or from the network, causing an out-of-bounds write, resulting in a Denial of Service and limited memory corruption.

Отчет

The ISO 10681 dissector is not available in Wireshark shipped by Red Hat Enterprise Linux 8 and 9 but the ISO 15765 is available in Wireshark shipped by all versions of Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkWill not fix
Red Hat Enterprise Linux 9wiresharkWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2176452wireshark: ISO 15765 and ISO 10681 dissector crash

EPSS

Процентиль: 37%
0.00161
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
почти 3 года назад

ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file

CVSS3: 6.3
nvd
почти 3 года назад

ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file

CVSS3: 6.3
debian
почти 3 года назад

ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 an ...

suse-cvrf
почти 3 года назад

Security update for wireshark

CVSS3: 6.5
github
почти 3 года назад

ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file

EPSS

Процентиль: 37%
0.00161
Низкий

7.1 High

CVSS3