First published: Thu Dec 30 2021(Updated: )
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=3.4.0<=3.4.10 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4186 is a vulnerability in Wireshark 3.4.0 to 3.4.10 that allows denial of service through packet injection or crafted capture file.
CVE-2021-4186 affects Wireshark versions 3.4.0 to 3.4.10 by causing a crash in the Gryphon dissector and allowing denial of service.
CVE-2021-4186 has a severity rating of 7.5 out of 10, indicating a high level of threat.
Denial of service can occur through CVE-2021-4186 by exploiting the vulnerability in the Gryphon dissector in Wireshark, either through packet injection or using a crafted capture file.
Yes, updating Wireshark to a version beyond 3.4.10 will fix the vulnerability CVE-2021-4186.