MEDIUM 4.3 Microsoft
CVE-2022-4344
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
Microsoft Security Update 2023-Jan: Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
Affected Products
- cbl2 wireshark 4.0.8-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-4344
- https://nvd.nist.gov/vuln/detail/CVE-2022-4344
This medium severity vulnerability with a CVSS score of 4.3 was published on 2023-01-10 via Microsoft. Affected: cbl2 wireshark 4.0.8-1 on CBL Mariner 2.0.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.