NetScreen File Parser Denial of Service Vulnerability
CVE-2023-6175

7.8HIGH

Key Information:

Vendor
Wireshark
Status
Vendor
CVE Published:
26 March 2024

Summary

A vulnerability in Wireshark's handling of NetScreen file parsing can lead to a denial of service condition. This flaw is present in Wireshark versions 4.0.0 through 4.0.10 and 3.6.0 to 3.6.18. Attackers can exploit this vulnerability by crafting malicious capture files that trigger a crash when processed by Wireshark, potentially disrupting network analysis activities and impacting system availability.

Affected Version(s)

Wireshark 4.0.0 < 4.0.11

Wireshark 3.6.0 < 3.6.19

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous working with Trend Micro Zero Day Initiative
.