QID 375489
Date Published: 2021-04-26
QID 375489: Wireshark Protocol Memory Consumption Vulnerability (wnpa-sec-2021-04)
Wireshark is a network protocol analyzer available for multiple operating systems. It lets you capture and interactively browse the traffic running on a computer network.
The MS-WSP dissector could consume excessive amounts of memory.
Affected version:
Wireshark Version: 3.4.0 to 3.4.4, 3.2.0 to 3.2.12
QID Detection Logic (Authenticated):
Windows: wireshark.exe file version is checked,
MAC OSX: Wireshark app version is checked.
Successful exploitation of this vulnerability may allow an attacker to consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Solution
Vendor has released a patch for Wireshark 3.4.5, 3.2.13 or later addressing this vulnerability.
For more details please visit Wireshark 3.4.5.Wireshark 3.2.13
For more details please visit Wireshark 3.4.5.Wireshark 3.2.13
Vendor References
- wnpa-sec-2021-04 -
www.wireshark.org/security/wnpa-sec-2021-04.html
CVEs related to QID 375489
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| wireshark-3.2.13 |
|
||
| wireshark-3.4.5 |
|