CVE-2023-2906

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

History

15 Sep 2023, 22:15

Type Values Removed Values Added
References
  • (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRKHFQPWFU7F3OXTL6IEIQSJG6FVXZTZ/ -

09 Sep 2023, 04:15

Type Values Removed Values Added
References
  • (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HCUPLDY7HLPO46PHMGIJSUBJFTT237C/ -
  • (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L4AVRUYSHDNEAJILVSGY5W6MPOMG2YRF/ -

31 Aug 2023, 18:45

Type Values Removed Values Added
CWE CWE-369
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://gitlab.com/wireshark/wireshark/-/issues/19229 - (MISC) https://gitlab.com/wireshark/wireshark/-/issues/19229 - Exploit, Issue Tracking, Patch, Third Party Advisory
References (MISC) https://takeonme.org/cves/CVE-2023-2906.html - (MISC) https://takeonme.org/cves/CVE-2023-2906.html - Exploit, Third Party Advisory
First Time Wireshark
Wireshark wireshark
CPE cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

25 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-25 21:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-2906

Mitre link : CVE-2023-2906

CVE.ORG link : CVE-2023-2906


JSON object : View

Products Affected

wireshark

  • wireshark
CWE
CWE-369

Divide By Zero