Medium severity5.3NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-2854
CVE-2023-2854
Description
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords4 versionspkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweedpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6
< 4.2.6-150600.18.6.1+ 3 more
- (no CPE)range: < 4.2.6-150600.18.6.1
- (no CPE)range: < 4.0.6-1.1
- (no CPE)range: < 4.2.6-150600.18.6.1
- (no CPE)range: < 4.2.6-150600.18.6.1
Patches
Vulnerability mechanics
References
5- gitlab.com/wireshark/wireshark/-/issues/19084nvdExploitIssue TrackingPatchThird Party Advisory
- gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2854.jsonnvdThird Party Advisory
- security.gentoo.org/glsa/202309-02nvdThird Party Advisory
- www.debian.org/security/2023/dsa-5429nvdThird Party Advisory
- www.wireshark.org/security/wnpa-sec-2023-17.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.