6.5
CVE-2023-0666
- EPSS 2.28%
- Veröffentlicht 07.06.2023 03:15:09
- Zuletzt bearbeitet 03.11.2025 22:16:03
- CVE-Watchlists
- Unerledigt
Wireshark RTPS Parsing Buffer Overflow
Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version12.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.28% | 0.817 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://security.gentoo.org/glsa/202309-02
https://www.debian.org/security/2023/dsa-5429
https://gitlab.com/wireshark/wireshark/-/issues/19085
https://takeonme.org/cves/CVE-2023-0666.html
https://www.wireshark.org/docs/relnotes/wireshark-4.0.6.html
https://www.wireshark.org/security/wnpa-sec-2023-18.html
https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html