CVE-2021-4190: High severity wireshark vulnerability
Published Dec 30, 2021
·Updated
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
Affected Software
4 affected components
Wireshark Wireshark>=3.4.0<3.4.12
Wireshark Wireshark=3.6.0
fedoraproject fedora=34
fedoraproject fedora=35
Remediation
Patch Available
Event History
Dec 30, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-4190?
CVE-2021-4190 refers to a vulnerability in the Kafka dissector in Wireshark 3.6.0 that allows denial of service via packet injection or crafted capture file.
2
How does CVE-2021-4190 impact Wireshark?
CVE-2021-4190 can lead to denial of service attacks on Wireshark 3.6.0 through packet injection or maliciously crafted capture files.
3
What is the severity of CVE-2021-4190?
CVE-2021-4190 has a severity rating of 7.5 (high).
4
Which software versions are affected by CVE-2021-4190?
Wireshark versions 3.4.0 to 3.4.12 and version 3.6.0 are affected by CVE-2021-4190.
5
How can I fix CVE-2021-4190?
Updating Wireshark to a version beyond 3.6.0 or applying the necessary patches will fix CVE-2021-4190.