PT-2023-3430 · Wireshark+4 · Wireshark+4

CVE-2023-1993

·

Published

2023-04-12

·

Updated

2024-09-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.6.0 through 3.6.12 Wireshark versions 4.0.0 through 4.0.4
Description The issue is related to a large loop in the LISP dissector of Wireshark, which can lead to a denial of service via packet injection or crafted capture file. This can be exploited by a remote attacker to cause a service disruption.
Recommendations For Wireshark versions 3.6.0 through 3.6.12, update to a version that fixes this issue. For Wireshark versions 4.0.0 through 4.0.4, update to a version that fixes this issue. As a temporary workaround, consider disabling the LISP dissector until a patch is available.

Exploit

Fix

DoS

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1747
ALT-PU-2023-1771
ALT-PU-2023-5823
ALT-PU-2023-6556
BDU:2023-03347
BDU:2023-03609
CVE-2023-1993
DLA-3402-1
DLA-3906-1
DSA-5429-1
OESA-2023-1260
OESA-2023-1261
OPENSUSE-SU-2024:12865-1
ROSA-SA-2023-2257
ROSA-SA-2024-2388
SUSE-SU-2023:1931-1

Affected Products

Alt Linux
Astra Linux
Red Os
Suse
Wireshark