Bugzilla – Bug 1211708
VUL-0: CVE-2023-2854: wireshark: BLF file parser crash
Last modified: 2023-05-31 08:10:26 UTC
CVE-2023-2854 Summary Name: BLF file parser crash Docid: wnpa-sec-2023-17 Date: May 24, 2023 Affected versions: 4.0.0 to 4.0.5 Fixed versions: 4.0.6 References: Wireshark issue 19084. CVE-2023-2854. Details Description The BLF file parser could crash. Discovered by Huascar Tejeda. Impact It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Resolution Upgrade to Wireshark 4.0.6 or later. References: https://gitlab.com/wireshark/wireshark/-/issues/19084 https://www.wireshark.org/security/wnpa-sec-2023-17
SLE not affected, closing.