CVE-2023-0667
Wireshark MSMMS parsing buffer overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark
Debido a un fallo en la validación de la longitud proporcionada por un atacante en un paquete manipulado MSMMS, Wireshark v4.0.5 y anteriores, en una configuración inusual, es susceptible a un desbordamiento de búfer de pila, y posiblemente a la ejecución de código en el contexto del proceso que ejecuta Wireshark.
Multiple vulnerabilities have been found in Wireshark, the worst of which could result in denial of service. Versions greater than or equal to 4.0.6 are affected.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-02-03 CVE Reserved
- 2023-06-07 CVE Published
- 2025-02-13 CVE Updated
- 2025-02-13 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
- CAPEC-100: Overflow Buffers
References (3)
URL | Tag | Source |
---|---|---|
https://security.gentoo.org/glsa/202309-02 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://gitlab.com/wireshark/wireshark/-/issues/19086 | 2025-02-13 | |
https://takeonme.org/cves/CVE-2023-0667.html | 2025-02-13 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | >= 4.0.0 < 4.0.6 Search vendor "Wireshark" for product "Wireshark" and version " >= 4.0.0 < 4.0.6" | - |
Affected
|