VulnerabilityModified
CVE-2023-1993
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
MEDIUM 6.5EPSS 4.09%
Does this matter?
Lower severity and a low EPSS score (4.09%). Track it; it rarely justifies an emergency change on its own.
Description
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 4.09% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-834
- Affected
- wireshark/wireshark · debian/debian linux · fedoraproject/fedora
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1993.jsonThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/18900Exploit, Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00029.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3/
- https://security.gentoo.org/glsa/202309-02Third Party Advisory
- https://www.debian.org/security/2023/dsa-5429Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-10.htmlVendor Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1993.jsonThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/18900Exploit, Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00029.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3/
- https://security.gentoo.org/glsa/202309-02Third Party Advisory
- https://www.debian.org/security/2023/dsa-5429Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-10.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.