CVE Vulnerabilities

CVE-2023-5371

Memory Allocation with Excessive Size Value

Published: Oct 04, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file

Weakness

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 3.6.0 (including) 3.6.17 (excluding)
Wireshark Wireshark 4.0.0 (including) 4.0.9 (excluding)
Wireshark Ubuntu bionic *
Wireshark Ubuntu lunar *
Wireshark Ubuntu mantic *
Wireshark Ubuntu trusty *
Wireshark Ubuntu trusty/esm *
Wireshark Ubuntu xenial *

Potential Mitigations

References