XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
References
Configurations
History
03 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 07:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2952.json - Third Party Advisory | |
| References | () https://gitlab.com/wireshark/wireshark/-/issues/19100 - Exploit | |
| References | () https://lists.debian.org/debian-lts-announce/2023/06/msg00004.html - Mailing List, Third Party Advisory | |
| References | () https://security.gentoo.org/glsa/202309-02 - Third Party Advisory | |
| References | () https://www.debian.org/security/2023/dsa-5429 - Third Party Advisory | |
| References | () https://www.wireshark.org/security/wnpa-sec-2023-20.html - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
20 Oct 2023, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | |
| References | (GENTOO) https://security.gentoo.org/glsa/202309-02 - Third Party Advisory | |
| References | (MLIST) https://lists.debian.org/debian-lts-announce/2023/06/msg00004.html - Mailing List, Third Party Advisory | |
| References | (DEBIAN) https://www.debian.org/security/2023/dsa-5429 - Third Party Advisory |
17 Sep 2023, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Jun 2023, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Jun 2023, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MLIST) https://lists.debian.org/debian-lts-announce/2023/06/msg00004.html - Mailing List | |
| References | (MISC) https://gitlab.com/wireshark/wireshark/-/issues/19100 - Exploit | |
| References | (CONFIRM) https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2952.json - Third Party Advisory | |
| References | (MISC) https://www.wireshark.org/security/wnpa-sec-2023-20.html - Vendor Advisory | |
| First Time |
Debian debian Linux
Wireshark Debian Wireshark wireshark |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* |
|
| CWE | CWE-835 |
03 Jun 2023, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 May 2023, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-05-30 23:15
Updated : 2025-11-03 22:16
NVD link : CVE-2023-2952
Mitre link : CVE-2023-2952
CVE.ORG link : CVE-2023-2952
JSON object : View
Products Affected
debian
- debian_linux
wireshark
- wireshark
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
