CVE-2021-39920: Null Pointer Dereference
Published Nov 18, 2021
·Updated
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
Affected Software
4 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=3.4.0<3.4.10
fedoraproject fedora=34
fedoraproject fedora=35
Event History
Nov 18, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-39920?
CVE-2021-39920 is a vulnerability in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 that allows denial of service through packet injection or crafted capture file.
2
How does CVE-2021-39920 affect Wireshark?
CVE-2021-39920 affects Wireshark versions 3.4.0 to 3.4.9, allowing denial of service via packet injection or crafted capture file.
3
What is the severity of CVE-2021-39920?
CVE-2021-39920 has a severity level of 7.5 (high).
4
How can I fix CVE-2021-39920 in Wireshark?
To fix CVE-2021-39920, update Wireshark to version 3.4.10 or later.
5
Are there any references for CVE-2021-39920?
Yes, you can find more information about CVE-2021-39920 at the following references: [Link 1], [Link 2], [Link 3].