
Cloud Vulnerability DB
A community-led vulnerabilities database
A dissection engine bug was discovered in Wireshark versions 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10. The vulnerability was identified on January 18, 2023, and was assigned CVE-2023-0413. The issue affects the conversation tracking module in Wireshark's dissection engine (Wireshark Advisory).
The vulnerability stems from a bug in the conversation tracking module of Wireshark's dissection engine. The issue affects multiple dissectors that interact with this module, potentially leading to application crashes when processing certain network traffic (Wireshark Advisory, NVD).
The vulnerability allows for denial of service attacks against Wireshark installations. When exploited, it can cause the application to crash during packet processing, disrupting network traffic analysis capabilities (NVD, Debian LTS).
The vulnerability has been fixed in Wireshark versions 4.0.3 and 3.6.11. Users are advised to upgrade to these or later versions to protect against this vulnerability. For Debian 10 (buster) users, the fix is available in version 2.6.20-0+deb10u5 (Wireshark Advisory, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."