CVE-2023-0667
Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark
- Affected products
- Alt Linux, Astra Linux, Suse, Wireshark
- Wireshark
- < 4.0.6
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 2.0% (80th percentile)
- Weakness
- CWE-787, CWE-122
- NVD status
- Modified
- Published
- 2023-06-07
- Attack patterns
- CAPEC-100
CVE-2023-0667 at NVD
No indexed exploits for CVE-2023-0667 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-0667 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.