6.5
CVE-2023-1994
- EPSS 1%
- Veröffentlicht 12.04.2023 22:15:13
- Zuletzt bearbeitet 03.11.2025 22:16:04
- Erkennungen
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 12.0
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 37
Fedoraproject ≫ Fedora Version 38
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1% | 0.583 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| cve@gitlab.com | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://security.gentoo.org/glsa/202309-02
https://lists.debian.org/debian-lts-announce/2023/04/msg00029.html
https://www.debian.org/security/2023/dsa-5429
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3/
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1994.json
https://gitlab.com/wireshark/wireshark/-/issues/18947
https://www.wireshark.org/security/wnpa-sec-2023-11.html
https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html