QID 376111

Date Published: 2021-11-29

QID 376111: Wireshark Bluetooth HCI_ISO Dissector Crash Vulnerability (wnpa-sec-2021-08)

Wireshark is a network protocol analyzer available for multiple operating systems. It lets you capture and interactively browse the traffic running on a computer network.

The Bluetooth HCI_ISO dissector could crash.

Affected version:
Wireshark Version: 3.4.0 to 3.4.9.

It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released a patch for Wireshark 3.4.10 or later addressing this vulnerability.
    For more details please visit Wireshark.
    Vendor References

    CVEs related to QID 376111

    Software Advisories
    Advisory ID Software Component Link
    wnpa-sec-2021-08 URL Logo www.wireshark.org/security/wnpa-sec-2021-08.html