6.5
CVSSv3

CVE-2023-1994

Published: 12/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark

debian debian linux 10.0

debian debian linux 12.0

fedoraproject fedora 36

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1034721 wireshark: CVE-2023-1992 CVE-2023-1993 CVE-2023-1994 Package: src:wireshark; Maintainer for src:wireshark is Balint Reczey <balint@balintreczeyhu>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 22 Apr 2023 17:33:02 UTC Severity: important Tags: security, upstream Foun ...
Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code For the stable distribution (bookworm), these problems have been fixed in version 406-1~deb12u1 We recommend that you upgrade your wireshark packages For the detailed security statu ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...