CVE-2022-0585: Medium severity wireshark vulnerability
Published Feb 18, 2022
·Updated
Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file
Affected Software
5 affected components
Wireshark Wireshark>=3.4.0<3.4.12
Wireshark Wireshark>=3.6.0<3.6.2
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=9.0
Event History
Feb 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-0585?
CVE-2022-0585 is a vulnerability in Wireshark versions 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 that allows denial of service through packet injection or crafted capture file.
2
How does CVE-2022-0585 impact Wireshark?
CVE-2022-0585 can result in a denial of service by causing large loops in multiple protocol dissectors.
3
What is the severity of CVE-2022-0585?
CVE-2022-0585 has a severity rating of medium (6.5) in the CVSS v3.1 scoring system.
4
Which software versions are affected by CVE-2022-0585?
Wireshark versions 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 are affected by CVE-2022-0585.
5
How can I mitigate the impact of CVE-2022-0585?
To mitigate the impact of CVE-2022-0585, update to Wireshark versions 3.6.2 or higher for the 3.6.x branch, or 3.4.12 or higher for the 3.4.x branch.