CVE-2021-22207: Medium severity wireshark vulnerability
Published Apr 23, 2021
·Updated
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
Affected Software
9 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.2.0<=3.2.12
Wireshark Wireshark>=3.4.0<=3.4.4
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Oracle ZFS Storage Appliance Kit=8.8
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Apr 23, 2021
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22207?
CVE-2021-22207 is a vulnerability in Wireshark that allows denial of service through excessive memory consumption.
2
Which versions of Wireshark are affected by CVE-2021-22207?
Wireshark versions 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 are affected by CVE-2021-22207.
3
What is the severity of CVE-2021-22207?
CVE-2021-22207 has a severity rating of 6.5 (medium).
4
How can CVE-2021-22207 be exploited?
CVE-2021-22207 can be exploited through packet injection or a crafted capture file.
5
Is there a fix for CVE-2021-22207?
Yes, upgrading to Wireshark version 4.0.10 or applying the recommended patches for affected versions resolves CVE-2021-22207.