VulnerabilityModified
CVE-2023-2856
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
MEDIUM 6.5EPSS 1.79%
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- wireshark/wireshark · debian/debian linux
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2856.jsonThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/19083Exploit, Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00004.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202309-02Third Party Advisory
- https://www.debian.org/security/2023/dsa-5429Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-16.htmlVendor Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2856.jsonThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/19083Exploit, Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00004.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://security.gentoo.org/glsa/202309-02Third Party Advisory
- https://www.debian.org/security/2023/dsa-5429Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-16.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.