CERT-In Vulnerability Note
CIVN-2021-0384
Multiple Vulnerabilities in Wireshark
Original Issue Date:December 31, 2021
Severity Rating: HIGH
Software Affected
- Wireshark version prior to 3.4.11
Overview
Multiple vulnerabilities have been reported in Wireshark which could allow a remote attacker to cause denial of service conditions on a targeted system.
Description
These vulnerabilities exists in Wireshark due to Sysdig Event dissector, Gryphon dissector, RFC 7468 file parser, BitTorrent DHT dissector and RTMPT dissector which may cause a crash in the application or go into an infinite loop. A remote attacker could exploit these vulnerabilities by injecting a malformed packet onto the wire or by convincing the user to read a malformed packet trace file.
Successful exploitation of these vulnerabilities could allow the attacker to cause denial of service conditions on the targeted system.
Solution
- Upgrade to Wireshark version 3.4.11 or later.
Vendor Information
Wireshark
https://www.wireshark.org/docs/relnotes/wireshark-3.4.11.html
https://www.wireshark.org/security/wnpa-sec-2021-16
https://www.wireshark.org/security/wnpa-sec-2021-17
https://www.wireshark.org/security/wnpa-sec-2021-18
https://www.wireshark.org/security/wnpa-sec-2021-20
https://www.wireshark.org/security/wnpa-sec-2021-21
References
Wireshark
https://www.wireshark.org/docs/relnotes/wireshark-3.4.11.html
https://www.wireshark.org/security/wnpa-sec-2021-16
https://www.wireshark.org/security/wnpa-sec-2021-17
https://www.wireshark.org/security/wnpa-sec-2021-18
https://www.wireshark.org/security/wnpa-sec-2021-20
https://www.wireshark.org/security/wnpa-sec-2021-21
https://www.tenable.com/plugins/nessus/156390
CVE Name
CVE-2021-4181
CVE-2021-4182
CVE-2021-4184
CVE-2021-4185
CVE-2021-4186
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|