CVE-2021-22235: High severity wireshark vulnerability
Published Jul 20, 2021
·Updated
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
Affected Software
6 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.2.0<3.2.15
Wireshark Wireshark>=3.4.0<3.4.7
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Jul 20, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-22235?
CVE-2021-22235 is a vulnerability in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 that allows denial of service via packet injection or a crafted capture file.
2
How can the CVE-2021-22235 vulnerability impact my system?
The CVE-2021-22235 vulnerability can result in a crash in the DNP dissector in Wireshark, leading to a denial of service.
3
What is the severity of CVE-2021-22235?
The severity of CVE-2021-22235 is high with a severity value of 7.5.
4
Which versions of Wireshark are affected by CVE-2021-22235?
Wireshark versions 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 are affected by CVE-2021-22235.
5
How do I mitigate the CVE-2021-22235 vulnerability?
To mitigate the CVE-2021-22235 vulnerability, update Wireshark to version 3.4.10-0+deb11u1, 4.0.6-1~deb12u1, or 4.0.10-1.