CVE-2022-4345
Published on: Not Yet Published
Last Modified on: 02/11/2023 04:15:00 AM UTC
Certain versions of Wireshark from Wireshark contain the following vulnerability:
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
- CVE-2022-4345 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Wireshark Foundation - Wireshark version >=4.0.0, <4.0.2
- Affected Vendor/Software:
Wireshark Foundation - Wireshark version >=3.6.0, <3.6.10
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] [DLA 3313-1] wireshark security update | lists.debian.org text/html |
![]() |
Wireshark · wnpa-sec-2022-09 · Multiple dissector infinite loops | www.wireshark.org text/html |
![]() |
2022/CVE-2022-4345.json · master · GitLab.org / cves · GitLab | gitlab.com text/html |
![]() |
[SECURITY] Fedora 37 Update: wireshark-4.0.3-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 36 Update: wireshark-3.6.11-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Related QID Numbers
- 181549 Debian Security Update for wireshark (DLA 3313-1)
- 183867 Debian Security Update for wireshark (CVE-2022-4345)
- 283695 Fedora Security Update for wireshark (FEDORA-2023-9ddb9b9757)
- 283697 Fedora Security Update for wireshark (FEDORA-2023-f9e2ad8b73)
- 355179 Amazon Linux Security Advisory for wireshark : ALAS2023-2023-120
- 355407 Amazon Linux Security Advisory for wireshark : ALAS2023-2023-199
- 753670 SUSE Enterprise Linux Security Update for wireshark (SUSE-SU-2023:0343-1)
Exploit/POC from Github
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 al…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Wireshark | Wireshark | All | All | All | All |
- cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*:
Discovery Credit
Sharon Brizinov
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-4345 : Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and… twitter.com/i/web/status/1… | 2023-01-12 04:07:45 |
![]() |
CVE-2022-4345 | 2023-01-12 05:38:59 |