CVE-2021-39923: High severity wireshark vulnerability
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-39923?
CVE-2021-39923 is a vulnerability in the PNRP dissector in Wireshark versions 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 that allows denial of service through packet injection or crafted capture file.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending specially crafted packets or by using a manipulated capture file to cause a denial of service on a vulnerable system.
What is the severity of CVE-2021-39923?
CVE-2021-39923 has a severity rating of 7.5 (high).
Which versions of Wireshark are affected by CVE-2021-39923?
Wireshark versions 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 are affected by CVE-2021-39923.
How do I fix CVE-2021-39923?
To fix CVE-2021-39923, it is recommended to update to the latest version of Wireshark (4.0.10-1 or later) or apply the provided patches and security updates from the official sources.