CVE-2021-22235Infinite Loop in Wireshark

CWE-835Infinite Loop7 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.8%
top 26.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 24

Description

Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDwireshark/wireshark3.2.03.2.15+1
Debianwireshark/wireshark< 3.4.10-0+deb11u1+3
CVEListV5the_wireshark_foundation/wireshark>=3.2.0, <3.2.15, >=3.4.0, <3.4.7+1

Also affects: Debian Linux 10.0, 11.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-c9h4-m6h9-v7wx: Crash in DNP dissector in Wireshark 32022-05-24
OSV
CVE-2021-22235: Crash in DNP dissector in Wireshark 32021-07-20
CVEList
CVE-2021-22235: Crash in DNP dissector in Wireshark 32021-07-20

📋Vendor Advisories

3
Red Hat
wireshark: DNP dissector crash2021-07-16
Microsoft
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file2021-07-13
Debian
CVE-2021-22235: wireshark - Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows de...2021
CVE-2021-22235 — Infinite Loop in Wireshark | cvebase