PT-2021-6886 · Wireshark+3 · Wireshark+3
Published
2021-11-29
·
Updated
2024-09-30
·
CVE-2021-4184
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 3.4.0 through 3.4.10
Wireshark version 3.6.0
Description
The issue is related to an infinite loop in the BitTorrent DHT dissector, which can be exploited to cause a denial of service via packet injection or crafted capture file. This can be achieved by sending specially crafted packets, allowing a remote attacker to disrupt the service.
Recommendations
For Wireshark versions 3.4.0 through 3.4.10, consider disabling the BitTorrent DHT dissector until a patch is available.
For Wireshark version 3.6.0, consider disabling the BitTorrent DHT dissector until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Suse
Wireshark