Input validation error in Wireshark - CVE-2023-2854

 

Input validation error in Wireshark - CVE-2023-2854

Published: May 25, 2023


Vulnerability identifier: #VU76495
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2854
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in BLF file parser. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Wireshark
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Oracle Solaris
Basesystem Module
Desktop Applications Module
openSUSE Leap
net-analyzer/wireshark
wireshark
wireshark (Debian package)
wireshark-devel
wireshark-debuginfo
libwiretap14
wireshark-ui-qt
libwireshark17
libwsutil15-debuginfo
libwsutil15
libwireshark17-debuginfo
libwiretap14-debuginfo
wireshark-debugsource
wireshark-ui-qt-debuginfo

How to mitigate CVE-2023-2854

Install updates from vendor's website.

Wireshark - update to 4.0.6
net-analyzer/wireshark - update to 4.0.6
wireshark - update to 4.0.6-1
wireshark (Debian package) - update to 4.0.6-1~deb12u1
wireshark-devel - update to 4.2.6-150600.18.6.1
wireshark-debuginfo - update to 4.2.6-150600.18.6.1
libwiretap14 - update to 4.2.6-150600.18.6.1
wireshark - update to 4.2.6-150600.18.6.1
wireshark-ui-qt - update to 4.2.6-150600.18.6.1
libwireshark17 - update to 4.2.6-150600.18.6.1
libwsutil15-debuginfo - update to 4.2.6-150600.18.6.1
libwsutil15 - update to 4.2.6-150600.18.6.1
libwireshark17-debuginfo - update to 4.2.6-150600.18.6.1
libwiretap14-debuginfo - update to 4.2.6-150600.18.6.1
wireshark-debugsource - update to 4.2.6-150600.18.6.1
wireshark-ui-qt-debuginfo - update to 4.2.6-150600.18.6.1

External References

Related Security Bulletins