Denial of Service Vulnerability in Wireshark by The Wireshark Foundation
CVE-2021-4185
7.5HIGH
Summary
An infinite loop in the RTMPT dissector of Wireshark allows attackers to cause a denial of service by injecting crafted packets or through specially designed capture files. This vulnerability impacts multiple versions of Wireshark, making it critical for users to ensure their software is up to date to mitigate potential exploits.
Affected Version(s)
Wireshark =3.6.0 = 3.6.0
Wireshark >=3.4.0, <3.4.10 < 3.4.0, 3.4.10
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved