Wireshark CP2179 divide by zero
Published Aug 25, 2023
6.5
MEDIUMCVSS 3.1
EPSS 2.79%
Description
Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.
Affected products
-
- Version 2.0.0StatusaffectedConstraints<=4.0.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | unaffected |
|
No data.
Red Hat Enterprise Linux 6
wireshark
Affected
Red Hat Enterprise Linux 7
wireshark
Will not fix
Red Hat Enterprise Linux 8
wireshark
Will not fix
Red Hat Enterprise Linux 9
wireshark
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/network-tools-rhel9
Not affected
Red Hat OpenShift Container Platform 4
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Affected | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/network-tools-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2023-2906 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2235363 Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/issues/19229 patchExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HCUPLDY7HLPO46PHMGIJSUBJFTT237C/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L4AVRUYSHDNEAJILVSGY5W6MPOMG2YRF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRKHFQPWFU7F3OXTL6IEIQSJG6FVXZTZ/
- https://nvd.nist.gov/vuln/detail/CVE-2023-2906
- https://takeonme.org/cves/CVE-2023-2906.html exploitthird-party-advisorytechnical-descriptionThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-2906
Change history (0)
No recorded changes yet.