Denial of Service Vulnerability in Wireshark by The Wireshark Foundation
CVE-2021-4185

7.5HIGH

Key Information:

Vendor
Wireshark
Status
Vendor
CVE Published:
30 December 2021

Summary

An infinite loop in the RTMPT dissector of Wireshark allows attackers to cause a denial of service by injecting crafted packets or through specially designed capture files. This vulnerability impacts multiple versions of Wireshark, making it critical for users to ensure their software is up to date to mitigate potential exploits.

Affected Version(s)

Wireshark =3.6.0 = 3.6.0

Wireshark >=3.4.0, <3.4.10 < 3.4.0, 3.4.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.