VDB
CNVD-2023-62291
CNVD-2023-62291
PUBLISHED
CVSS 6.300000190734863 MEDIUM
Wireshark是一款具有流行度和影响力的开源协议分析器,常被用于网络故障排查、协议开发和教学等方面,其支持多种协议和数据格式。 Wireshark存在安全漏洞,攻击者可利用该漏洞对网络进行拒绝服务攻击,导致网络瘫痪。
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wireshark Foundation | Wireshark | >=4.0.0, <4.0.6, >=3.6.0, <3.6.14 |
Exploit Intelligence
- CIRCL published-proof-of-concept: CVE-2023-2879 (circl-sighting)
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html (circl)
- https://www.wireshark.org/security/wnpa-sec-2023-14.html (circl)
- https://gitlab.com/wireshark/wireshark/-/issues/19068 (circl)
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2879.json (circl)
- [debian-lts-announce] 20230603 [SECURITY] [DLA 3443-1] wireshark security update (circl)
- DSA-5429 (circl)
- GLSA-202309-02 (circl)
Timeline
- May 26, 2023 CVE Published
- May 30, 2023 CVE ID Reserved
- Jan 15, 2025 PoC Published
- May 2, 2026 Distribution Patch
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://www.wireshark.org/security/wnpa-sec-2023-14.html url
- https://gitlab.com/wireshark/wireshark/-/issues/19068 url
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2879.json url
- [debian-lts-announce] 20230603 [SECURITY] [DLA 3443-1] wireshark security update mailing-list
- DSA-5429 vendor-advisory
- GLSA-202309-02 vendor-advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html url