Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:7015

Опубликовано: 25 июн. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: wireshark security update

The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network.

Security Fix(es):

  • wireshark: RTPS dissector crash (CVE-2023-0666)

  • wireshark: VMS TCPIPtrace file parser crash (CVE-2023-2856)

  • wireshark: NetScaler file parser crash (CVE-2023-2858)

  • wireshark: XRA dissector infinite loop (CVE-2023-2952)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.9 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
wiresharkaarch6417.el8wireshark-2.6.2-17.el8.aarch64.rpm
wireshark-cliaarch6417.el8wireshark-cli-2.6.2-17.el8.aarch64.rpm
wiresharkx86_6417.el8wireshark-2.6.2-17.el8.x86_64.rpm
wireshark-clii68617.el8wireshark-cli-2.6.2-17.el8.i686.rpm
wireshark-clix86_6417.el8wireshark-cli-2.6.2-17.el8.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 2 лет назад

ELSA-2023-7015: wireshark security update (MODERATE)

oracle-oval
больше 2 лет назад

ELSA-2023-6469: wireshark security update (MODERATE)

CVSS3: 6.5
ubuntu
около 3 лет назад

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVSS3: 6.5
redhat
около 3 лет назад

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVSS3: 6.5
nvd
около 3 лет назад

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.