First published: Fri Nov 19 2021(Updated: )
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/wireshark | 2.6.20-0+deb10u4 2.6.20-0+deb10u7 3.4.10-0+deb11u1 4.0.6-1~deb12u1 4.0.10-1 | |
Wireshark Wireshark | >=3.2.0<=3.2.17 | |
Wireshark Wireshark | >=3.4.0<=3.4.9 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39921 is a vulnerability in the Modbus dissector in Wireshark that allows denial of service through packet injection or crafted capture file.
Wireshark versions 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 are affected by CVE-2021-39921.
CVE-2021-39921 can be exploited by performing packet injection or using a crafted capture file in Wireshark.
CVE-2021-39921 has a severity rating of high (7.5).
To fix CVE-2021-39921, update Wireshark to version 3.4.10 or higher.