Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22207

Опубликовано: 21 апр. 2021
Источник: redhat
CVSS3: 7.5

Описание

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

A flaw was found in wireshark. A memory leak in the MS-WSP dissector allows an attacker to crash an application which uses wireshark due to excessive memory allocation. The attacker can trigger the flaw by injecting special packets onto the wire or by convincing a victim user into opening a malformed packet trace file. The highest threat from this vulnerability is to application availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1952964wireshark: MS-WSP dissector excessive memory consumption

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

CVSS3: 5.5
nvd
почти 5 лет назад

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

CVSS3: 6.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.5
debian
почти 5 лет назад

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to ...

CVSS3: 6.5
github
больше 3 лет назад

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

7.5 High

CVSS3