CVE-2021-4185: High severity wireshark vulnerability
Published Dec 30, 2021
·Updated
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Affected Software
8 affected components
Wireshark Wireshark>=3.4.0<3.4.11
Wireshark Wireshark=3.6.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Oracle HTTP Server=12.2.1.3.0
Oracle HTTP Server=12.2.1.4.0
Oracle ZFS Storage Appliance Kit=8.8
Event History
Dec 30, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-4185?
CVE-2021-4185 is a vulnerability in Wireshark 3.6.0 and 3.4.0 to 3.4.10 that allows denial of service through packet injection or crafted capture file.
2
How does CVE-2021-4185 impact Wireshark?
CVE-2021-4185 can result in an infinite loop in the RTMPT dissector of Wireshark, leading to a denial of service.
3
What is the severity of CVE-2021-4185?
CVE-2021-4185 has a severity rating of 7.5 (High).
4
Which software versions are affected by CVE-2021-4185?
Wireshark versions 3.6.0 and 3.4.0 to 3.4.10 are affected by CVE-2021-4185.
5
How can I fix CVE-2021-4185?
To fix CVE-2021-4185, update to Wireshark version 3.4.11 or newer.