Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-0417: Wireshark · wnpa-sec-2023-02 · NFS dissector memory leak

Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

CVE
#dos

wnpa-sec-2023-02 · NFS dissector memory leak

Summary

Name: NFS dissector memory leak

Docid: wnpa-sec-2023-02

Date: January 18, 2023

Affected versions: 4.0.0 to 4.0.2, 3.6.0 to 3.6.10

Fixed versions: 4.0.3, 3.6.11

References:
Wireshark issue 18628

Details****Description

The NFS dissector could leak memory.

Impact

It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Resolution

Upgrade to Wireshark 4.0.3, 3.6.11 or later.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda