CVE-2021-4183Out-of-bounds Read in Foundation Wireshark

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 59.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30
Latest updateNov 29

Description

Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianwireshark/wireshark< 3.6.2-1+2
NVDoracle/http_server12.2.1.3.0, 12.2.1.4.0+1

Also affects: Fedora 34, 35

Patches

🔴Vulnerability Details

3
GHSA
GHSA-88qr-cjgj-jggp: Crash in the pcapng file parser in Wireshark 32021-12-31
CVEList
CVE-2021-4183: Crash in the pcapng file parser in Wireshark 32021-12-30
OSV
CVE-2021-4183: Crash in the pcapng file parser in Wireshark 32021-12-30

📋Vendor Advisories

3
Chrome
Stable Channel Update for Desktop: CVE-2022-41832022-11-29
Red Hat
wireshark: pcapng file parser crash2021-12-29
Debian
CVE-2021-4183: wireshark - Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via ...2021
CVE-2021-4183 — Out-of-bounds Read | cvebase