CVE-2023-0415
SUSE Security Advisory - SUSE-SU-2023:0343-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
El disector iSCSI falla en Wireshark 4.0.0 a 4.0.2 y 3.6.0 a 3.6.10 y permite la denegación de servicio mediante inyección de paquetes o archivo de captura manipulado.
An update that solves 7 vulnerabilities and has one errata is now available. This update for wireshark fixes the following issues. Fixed a memory leak in the NFS dissector. Fixed a crash in the dissection engine. Fixed a crash in the GNW dissector. Fixed a crash in the iSCSI dissector. Fixed several issues where an excessive CPU consumption could be triggered in multiple dissectors. Fixed a crash in the TIPC dissector.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-01-20 CVE Reserved
- 2023-01-24 CVE Published
- 2025-03-30 EPSS Updated
- 2025-04-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-404: Improper Resource Shutdown or Release
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0415.json | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2023/02/msg00007.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/wireshark/wireshark/-/issues/18796 | 2023-02-09 |
URL | Date | SRC |
---|---|---|
https://www.wireshark.org/security/wnpa-sec-2023-05.html | 2023-02-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | >= 3.6.0 <= 3.6.10 Search vendor "Wireshark" for product "Wireshark" and version " >= 3.6.0 <= 3.6.10" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | >= 4.0.0 <= 4.0.2 Search vendor "Wireshark" for product "Wireshark" and version " >= 4.0.0 <= 4.0.2" | - |
Affected
|