First published: Fri Nov 19 2021(Updated: )
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/wireshark | 2.6.20-0+deb10u4 2.6.20-0+deb10u7 3.4.10-0+deb11u1 4.0.6-1~deb12u1 4.0.10-1 | |
Wireshark Wireshark | >=3.2.0<=3.2.17 | |
Wireshark Wireshark | >=3.4.0<=3.4.9 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39923 is a vulnerability in the PNRP dissector in Wireshark versions 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 that allows denial of service through packet injection or crafted capture file.
This vulnerability can be exploited by sending specially crafted packets or by using a manipulated capture file to cause a denial of service on a vulnerable system.
CVE-2021-39923 has a severity rating of 7.5 (high).
Wireshark versions 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 are affected by CVE-2021-39923.
To fix CVE-2021-39923, it is recommended to update to the latest version of Wireshark (4.0.10-1 or later) or apply the provided patches and security updates from the official sources.