HIGH
wireshark: infinite loop in GDSDB dissector
Published May 26, 2023
7.5
HIGHCVSS 3.1
EPSS 1.59%
Description
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
Affected products
-
Affected
- ≥ 3.6.0, < 3.6.14
- ≥ 4.0.0, < 4.0.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Wireshark Foundation | Wireshark | unknown | Affected
|
Configuration 1
Configuration 2
OR
- 10.0
- 12.0
No data.
Red Hat Enterprise Linux 6
wireshark
Not affected
Red Hat Enterprise Linux 7
wireshark
Not affected
Red Hat Enterprise Linux 8
wireshark
Not affected
Red Hat Enterprise Linux 9
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- https://access.redhat.com/security/cve/CVE-2023-2879 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2210466 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34326 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2879.json Third Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/19068 ExploitIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/06/msg00004.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-2879
- https://security.gentoo.org/glsa/202309-02 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-2879
- https://www.debian.org/security/2023/dsa-5429 vendor-advisoryThird Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-14.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-2879 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2210466 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34326 | Advisory | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2879.json | Third Party Advisory | |
| https://gitlab.com/wireshark/wireshark/-/issues/19068 | ExploitIssue TrackingPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/06/msg00004.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-2879 | ||
| https://security.gentoo.org/glsa/202309-02 | vendor-advisoryThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-2879 | ||
| https://www.debian.org/security/2023/dsa-5429 | vendor-advisoryThird Party Advisory | |
| https://www.wireshark.org/security/wnpa-sec-2023-14.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published May 26, 2023
Updated Nov 3, 2025
Reserved May 25, 2023
Link CVE-2023-2879
CISA Vulnrichment
Updated Jan 15, 2025
GitHub
No data