CVE-2023-0668 is a heap-based buffer overflow vulnerability affecting Wireshark versions 4.0.5 and prior, specifically when processing attacker-crafted IEEE-C37.118 packets. This flaw stems from a failure to validate packet length, potentially leading to denial of service or arbitrary code execution within the Wireshark process. Rated as MEDIUM severity (CVSS 6.5), it requires user interaction (UI:R) and can be exploited remotely over the network (AV:N). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.6.0, < 3.6.14CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.6CPE matchmatch criteria | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
>= 3.6.0, <= 3.6.13CPE match | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
>= 4.0.0, <= 4.0.5CPE match | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.