HIGH
Uncontrolled Recursion in Wireshark
Published Aug 24, 2023
7.5
HIGHCVSS 3.1
EPSS 0.51%
Description
CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
Affected products
-
- Version 4.0.0StatusaffectedConstraints<4.0.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | n/a |
|
No data.
Red Hat Enterprise Linux 6
wireshark
Out of support scope
Red Hat Enterprise Linux 7
wireshark
Out of support scope
Red Hat Enterprise Linux 8
wireshark
Will not fix
Red Hat Enterprise Linux 9
wireshark
Will not fix
Red Hat OpenShift Container Platform 4
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.0.8 or above.
Weaknesses (1)
References (10)
- https://access.redhat.com/security/cve/CVE-2023-4512 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2235813 Issue Tracking
- https://gitlab.com/wireshark/wireshark/-/issues/19144 issue-trackingExploitIssue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6HCUPLDY7HLPO46PHMGIJSUBJFTT237C/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L4AVRUYSHDNEAJILVSGY5W6MPOMG2YRF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRKHFQPWFU7F3OXTL6IEIQSJG6FVXZTZ/
- https://nvd.nist.gov/vuln/detail/CVE-2023-4512
- https://www.cve.org/CVERecord?id=CVE-2023-4512
- https://www.wireshark.org/security/wnpa-sec-2023-23.html Issue TrackingVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Aug 24, 2023
Updated Mar 27, 2026
Reserved Aug 24, 2023
Link CVE-2023-4512
CISA Vulnrichment
Updated Aug 30, 2024