CVE-2021-4182: High severity wireshark vulnerability
Published Dec 30, 2021
·Updated
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Affected Software
7 affected components
Wireshark Wireshark>=3.4.0<3.4.11
Wireshark Wireshark=3.6.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Oracle HTTP Server=12.2.1.3.0
Oracle HTTP Server=12.2.1.4.0
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Event History
Dec 30, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-4182?
CVE-2021-4182 is a vulnerability in Wireshark versions 3.6.0 and 3.4.0 to 3.4.10 that allows denial of service via packet injection or crafted capture file.
2
How does CVE-2021-4182 affect Wireshark?
CVE-2021-4182 affects Wireshark versions 3.6.0 and 3.4.0 to 3.4.10, potentially leading to denial of service due to crashes in the RFC 7468 dissector.
3
What is the severity of CVE-2021-4182?
CVE-2021-4182 has a severity level of high, with a CVSS score of 7.5.
4
How can I exploit CVE-2021-4182?
CVE-2021-4182 can be exploited by injecting malicious packets or using a crafted capture file to crash Wireshark.
5
How can I mitigate CVE-2021-4182?
To mitigate CVE-2021-4182, it is recommended to update to Wireshark version 3.4.11 or later.