CVE-2021-22174: High severity wireshark vulnerability
Published Feb 17, 2021
·Updated
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
Affected Software
4 affected components
Wireshark Wireshark>=3.4.0<3.4.3
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Oracle ZFS Storage Appliance=8.8
Remediation
Patch Available
Event History
Feb 17, 2021
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22174?
CVE-2021-22174 is a vulnerability in Wireshark versions 3.4.0 to 3.4.2 that allows denial of service through packet injection or crafted capture file.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by injecting malicious packets or using a specially crafted capture file to crash the USB HID dissector in Wireshark.
3
What is the severity of CVE-2021-22174?
The severity of CVE-2021-22174 is high, with a CVSS score of 7.5.
4
Which software versions are affected by CVE-2021-22174?
Wireshark versions 3.4.0 to 3.4.2 are affected by CVE-2021-22174.
5
How can I fix CVE-2021-22174?
Upgrade to Wireshark version 3.4.3 or later to fix CVE-2021-22174.