Searching
..

Click anywhere to stop

KLA61753
Multiple vulnerabilities in Wireshark

Обновлено: 25/01/2024
Дата обнаружения
18/01/2023
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Wireshark. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in EAP dissector can be exploited to cause denial of service.
  2. Denial of service vulnerability in BPv6, NCP, and RTPS dissectors can be exploited to cause denial of service.
  3. Denial of service vulnerability in GNW dissector can be exploited to cause denial of service.
  4. Denial of service vulnerability in TIPC dissector can be exploited to cause denial of service.
  5. Information disclosure vulnerability in NFS dissector can be exploited to obtain sensitive information.
  6. Denial of service vulnerability in iSCSI dissector can be exploited to cause denial of service.
  7. Denial of service vulnerability in Some dissectors can be exploited to cause denial of service.
Пораженные продукты

Wireshark 3.6.x earlier than 3.6.11
Wireshark 4.0.x earlier than 4.0.3

Решение

Update to the latest version
Download Wireshark

Первичный источник обнаружения
Wireshark • wnpa-sec-2023-03 Dissection engine crash
Wireshark • wnpa-sec-2023-04 GNW dissector crash
Wireshark • wnpa-sec-2023-01 EAP dissector crash
Wireshark • wnpa-sec-2023-06 Multiple dissector excessive loops
Wireshark • wnpa-sec-2023-05 iSCSI dissector crash
Wireshark • wnpa-sec-2023-02 NFS dissector memory leak
Wireshark • wnpa-sec-2023-07 TIPC dissector crash
Оказываемое влияние
?
OSI 
[?]

DoS 
[?]
Связанные продукты
Wireshark
CVE-IDS
Узнай статистику распространения уязвимостей в твоем регионе