PT-2021-23448 · Wireshark+2 · Wireshark+2

Sharon Brizinov

·

Published

2021-12-30

·

Updated

2024-09-30

·

CVE-2021-4190

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark version 3.6.0
Description The issue is related to a large loop in the Kafka dissector, which allows for denial of service via packet injection or crafted capture file.
Recommendations For Wireshark version 3.6.0, consider disabling the Kafka dissector until a patch is available to prevent potential denial of service attacks.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1005
ALT-PU-2022-1096
ALT-PU-2022-1599
AZL-9100
CVE-2021-4190
DLA-3906-1
MGASA-2022-0068
OPENSUSE-SU-2022:0375-1
OPENSUSE-SU-2022_0375-1
OPENSUSE-SU-2024:11707-1
SUSE-SU-2022:0375-1

Affected Products

Alt Linux
Suse
Wireshark