{"id":"UBUNTU-CVE-2023-2854","details":"BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file","modified":"2025-07-16T07:45:55.055441Z","published":"2023-05-26T21:15:00Z","withdrawn":"2025-07-18T16:53:59Z","upstream":["CVE-2023-2854"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-2854"},{"type":"REPORT","url":"https://www.wireshark.org/security/wnpa-sec-2023-17.html"},{"type":"REPORT","url":"https://gitlab.com/wireshark/wireshark/-/issues/19084"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-2854"}],"affected":[{"package":{"name":"wireshark","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/wireshark@4.2.2-1.1build3?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.2-1.1build3"}]}],"versions":["4.0.8-1","4.0.10-1","4.0.11-1","4.2.0-1","4.2.2-1","4.2.2-1.1build1","4.2.2-1.1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libwireshark-data","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwireshark-dev","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwireshark17t64","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwireshark17t64-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwiretap-dev","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwiretap14t64","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwiretap14t64-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwsutil-dev","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwsutil15t64","binary_version":"4.2.2-1.1build3"},{"binary_name":"libwsutil15t64-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"tshark","binary_version":"4.2.2-1.1build3"},{"binary_name":"tshark-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark-common","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark-common-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark-dev","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark-dev-dbgsym","binary_version":"4.2.2-1.1build3"},{"binary_name":"wireshark-doc","binary_version":"4.2.2-1.1build3"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-2854.json"}},{"package":{"name":"wireshark","ecosystem":"Ubuntu:25.04","purl":"pkg:deb/ubuntu/wireshark@4.4.5-1?arch=source&distro=plucky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.5-1"}]}],"versions":["4.2.6-1","4.4.1-1","4.4.2-1","4.4.3-1","4.4.4-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libwireshark-data","binary_version":"4.4.5-1"},{"binary_name":"libwireshark-dev","binary_version":"4.4.5-1"},{"binary_name":"libwireshark18","binary_version":"4.4.5-1"},{"binary_name":"libwireshark18-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"libwiretap-dev","binary_version":"4.4.5-1"},{"binary_name":"libwiretap15","binary_version":"4.4.5-1"},{"binary_name":"libwiretap15-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"libwsutil-dev","binary_version":"4.4.5-1"},{"binary_name":"libwsutil16","binary_version":"4.4.5-1"},{"binary_name":"libwsutil16-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"tshark","binary_version":"4.4.5-1"},{"binary_name":"tshark-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"wireshark","binary_version":"4.4.5-1"},{"binary_name":"wireshark-common","binary_version":"4.4.5-1"},{"binary_name":"wireshark-common-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"wireshark-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"wireshark-dev","binary_version":"4.4.5-1"},{"binary_name":"wireshark-dev-dbgsym","binary_version":"4.4.5-1"},{"binary_name":"wireshark-doc","binary_version":"4.4.5-1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-2854.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}