Resource exhaustion in Wireshark - CVE-2023-6174
Published: November 16, 2023 / Updated: November 20, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the SSH dissector. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
Anolis OS
Fedora
wireshark
net-analyzer/wireshark
wireshark-doc
wireshark-devel
wireshark-cli
wireshark (Debian package)
wireshark-ui-qt
libwireshark17
libwsutil15-debuginfo
libwsutil15
libwireshark17-debuginfo
libwiretap14-debuginfo
wireshark-debugsource
wireshark-ui-qt-debuginfo
libwiretap14
wireshark-debuginfo
How to mitigate CVE-2023-6174
wireshark - update to 4.0.8-2
net-analyzer/wireshark - update to 4.0.11
wireshark-doc - update to 4.0.11-1
wireshark-devel - update to 4.0.11-1
wireshark-cli - update to 4.0.11-1
wireshark - update to 4.0.11-1
wireshark (Debian package) - update to 4.0.11-1~deb12u1
wireshark - addressed in versions 4.0.12-1.fc38, 4.0.12-1.fc39
wireshark-ui-qt - update to 4.2.6-150600.18.6.1
libwireshark17 - update to 4.2.6-150600.18.6.1
libwsutil15-debuginfo - update to 4.2.6-150600.18.6.1
libwsutil15 - update to 4.2.6-150600.18.6.1
libwireshark17-debuginfo - update to 4.2.6-150600.18.6.1
libwiretap14-debuginfo - update to 4.2.6-150600.18.6.1
wireshark-debugsource - update to 4.2.6-150600.18.6.1
wireshark-ui-qt-debuginfo - update to 4.2.6-150600.18.6.1
wireshark - update to 4.2.6-150600.18.6.1
libwiretap14 - update to 4.2.6-150600.18.6.1
wireshark-debuginfo - update to 4.2.6-150600.18.6.1
wireshark-devel - update to 4.2.6-150600.18.6.1