QID 375705
Date Published: 2021-07-26
QID 375705: Wireshark DNP Dissector Crash Vulnerability (wnpa-sec-2021-06)
Wireshark is a network protocol analyzer available for multiple operating systems. It lets you capture and interactively browse the traffic running on a computer network.
The DNP dissector could crash.
Affected version:
Wireshark Version: 3.4.0 to 3.4.6, 3.2.0 to 3.2.14
QID Detection Logic (Authenticated):
Windows: QID checks the file version of wireshark.exe
MAC OSX: QID checks the app version of Wireshark.
Successful exploitation of this vulnerability may allow an attacker to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Solution
Vendor has released a patch for Wireshark 3.4.7, 3.2.15 or later addressing this vulnerability.
For more details please visit Wireshark 3.4.7.Wireshark 3.2.15
For more details please visit Wireshark 3.4.7.Wireshark 3.2.15
Vendor References
- wnpa-sec-2021-06 -
www.wireshark.org/security/wnpa-sec-2021-06.html
CVEs related to QID 375705
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| wnpa-sec-2021-06 |
|