Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2906

Опубликовано: 25 авг. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

A vulnerability was found in Wireshark. This security issue occurs due to a failure to validate the length an attacker-crafted CP2179 packet provides. This flaw leaves Wireshark susceptible to a divide-by-zero problem, allowing a denial of service attack.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wiresharkAffected
Red Hat Enterprise Linux 7wiresharkWill not fix
Red Hat Enterprise Linux 8wiresharkWill not fix
Red Hat Enterprise Linux 9wiresharkWill not fix
Red Hat OpenShift Container Platform 4openshift4/network-tools-rhel9Not affected
Red Hat OpenShift Container Platform 4wiresharkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-396
https://bugzilla.redhat.com/show_bug.cgi?id=2235363wireshark: possible Denial of Service via crafted package

EPSS

Процентиль: 85%
0.02771
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

CVSS3: 6.5
nvd
почти 3 года назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

CVSS3: 6.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 3 года назад

Due to a failure in validating the length provided by an attacker-craf ...

CVSS3: 6.5
github
почти 3 года назад

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

EPSS

Процентиль: 85%
0.02771
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2023-2906