QID 375608
Date Published: 2021-06-07
QID 375608: Wireshark dissector infinite loop Vulnerability (wnpa-sec-2021-05)
Wireshark is a network protocol analyzer available for multiple operating systems. It lets you capture and interactively browse the traffic running on a computer network.
The DVB-S2-BB dissector could go into an infinite loop.
Affected version:
Wireshark Version: 3.4.0 to 3.4.5
QID Detection Logic (Authenticated):
Successful exploitation of this vulnerability may allow an attacker to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Solution
Vendor has released a patch for Wireshark 3.4.6 or later addressing this vulnerability.
For more details please visit Wireshark 3.4.6
For more details please visit Wireshark 3.4.6
Vendor References
- wnpa-sec-2021-05 -
www.wireshark.org/security/wnpa-sec-2021-05.html
CVEs related to QID 375608
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| wireshark-3.2.6 |
|