Severity
7.5HIGHNVD
EPSS
0.1%
top 68.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30
Latest updateDec 31

Description

Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDwireshark/wireshark3.4.03.4.12+1
Debianwireshark/wireshark< 3.4.16-0+deb11u1+3

Also affects: Fedora 34, 35

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pmc4-9968-jrp7: Large loop in the Kafka dissector in Wireshark 32021-12-31
CVEList
CVE-2021-4190: Large loop in the Kafka dissector in Wireshark 32021-12-30
OSV
CVE-2021-4190: Large loop in the Kafka dissector in Wireshark 32021-12-30

📋Vendor Advisories

5
Red Hat
wireshark: Kafka dissector infinite loop2021-12-29
Microsoft
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file2021-12-14
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability2021-09-14
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability2021-09-14
Debian
CVE-2021-4190: wireshark - Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service vi...2021
CVE-2021-4190 — Excessive Iteration in Wireshark | cvebase