Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
CVE-2023-4511

7.5HIGH

Key Information:

Vendor
Wireshark
Status
Vendor
CVE Published:
24 August 2023

Summary

A vulnerability in the BT SDP dissector component of Wireshark versions 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 permits an attacker to exploit an infinite loop via packet injection or by using a specially crafted capture file. This can result in a denial of service, disrupting the operation of the affected instances of Wireshark. For further details, refer to the official security advisory and the GitLab issue report.

Affected Version(s)

Wireshark 4.0.0 < 4.0.8

Wireshark 3.6.0 < 3.6.16

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chenyuan Mi
.