CVE-2021-22222: High severity wireshark vulnerability
Published Jun 7, 2021
·Updated
Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
Affected Software
9 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.4.0<=3.4.5
Oracle Enterprise Manager Ops Center=12.4.0.0
Oracle Instantis Enterprisetrack=17.1
Oracle Instantis Enterprisetrack=17.2
Oracle Instantis Enterprisetrack=17.3
Oracle ZFS Storage Appliance Kit=8.8
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Patch Available
Event History
Jun 7, 2021
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22222?
CVE-2021-22222 is a vulnerability in the DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 that allows denial of service via packet injection or crafted capture file.
2
How does CVE-2021-22222 impact Wireshark?
CVE-2021-22222 can cause Wireshark to enter an infinite loop, resulting in a denial of service.
3
What is the severity of CVE-2021-22222?
CVE-2021-22222 has a severity score of 7.5 (high).
4
Which versions of Wireshark are affected by CVE-2021-22222?
Wireshark versions 3.4.0 to 3.4.5 are affected by CVE-2021-22222.
5
How can I fix CVE-2021-22222?
To fix CVE-2021-22222, update Wireshark to version 3.4.6 or later.