MEDIUM
wireshark: GQUIC dissector crash
Published Apr 12, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.00%
Description
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Affected products
-
- Version >=3.6.0, <3.6.13StatusaffectedConstraints-
- Version >=4.0.0, <4.0.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | n/a |
|
Configuration 1
Configuration 2
OR
- 10.0
- 12.0
Configuration 3
OR
- 36
- 37
- 38
No data.
Red Hat Enterprise Linux 6
wireshark
Out of support scope
Red Hat Enterprise Linux 7
wireshark
Out of support scope
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- https://access.redhat.com/security/cve/CVE-2023-1994 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2186325 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-24174 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1994.json Third Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/18947 ExploitIssue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00029.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-1994
- https://security.gentoo.org/glsa/202309-02 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1994
- https://www.debian.org/security/2023/dsa-5429 vendor-advisoryThird Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-11.html Vendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 12, 2023
Updated Nov 3, 2025
Reserved Apr 11, 2023
Link CVE-2023-1994
CISA Vulnrichment
Updated Feb 7, 2025
ENISA EUVD
EUVD-2023-24174 Assigner GitLab
Published Apr 12, 2023
Updated Nov 3, 2025
Exploited since n/a
Link EUVD-2023-24174