QID 355161

Date Published: 2023-05-29

QID 355161: Amazon Linux Security Advisory for wireshark : ALAS2023-2023-038

a null pointer exception flaw was found in wireshark.
A process failure on crafted or malformed input in the ippusb dissector can cause a denial of service via a packet injection or a crafted capture file. (
( CVE-2021-39920) a null pointer exception flaw was found in wireshark.
A process failure on crafted or malformed input in the modbus dissector can cause a denial of service via a packet injection or crafted capture file. (
( CVE-2021-39921) a flaw was found in wireshark.
A process failure on crafted or malformed ansi c12.22 input can cause a denial of service via packet injection or a crafted capture file. (
( CVE-2021-39922) a flaw was found in wireshark.
A process failure consumes excessive cpu resources on crafted or malformed pnrp input and can cause a denial of service. (
( CVE-2021-39923) a flaw was found in wireshark.
A process failure on crafted or malformed bluetooth dht input can cause a denial of service via packet injection or a crafted capture file. (
( CVE-2021-39924) a flaw was found in wireshark.
A process failure on crafted or malformed bluetooth sdp input can cause a denial of service via packet injection or a crafted capture file. (
( CVE-2021-39925) a flaw was found in wireshark.
A process failure on crafted or malformed hci_iso input can cause a denial of service via packet injection or a crafted capture file. (

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-038 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-038 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-038.html