Unrated severityNVD Advisory· Published Apr 23, 2021· Updated Aug 3, 2024
CVE-2021-22207
CVE-2021-22207
Description
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
Affected products
52- osv-coords51 versionspkg:rpm/opensuse/sbc&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/libqt5-qtmultimedia&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/sbc&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/sbc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/sbc&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/sbc&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/sbc&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/wireshark&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/wireshark&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/wireshark&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/wireshark&distro=SUSE%20Manager%20Server%204.0
< 1.3-3.2.1+ 50 more
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 3.4.5-lp152.2.12.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.8-1.2
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 5.9.7-7.2.1
- (no CPE)range: < 4.0.0-9.37.21
- (no CPE)range: < 4.0.0-9.37.21
- (no CPE)range: < 4.0.0-9.37.21
- (no CPE)range: < 4.0.0-9.37.21
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 1.3-3.2.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- (no CPE)range: < 3.4.5-3.53.1
- The Wireshark Foundation/Wiresharkv5Range: >=3.4.0, <3.4.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIWWO27HV4HUKXV6NH6ULHCRAQB26DMD/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NL7ZTMMWIEPHHFK3ONRKATWE7CLIGLFD/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202107-21mitrevendor-advisoryx_refsource_GENTOO
- www.debian.org/security/2021/dsa-5019mitrevendor-advisoryx_refsource_DEBIAN
- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22207.jsonmitrex_refsource_CONFIRM
- gitlab.com/wireshark/wireshark/-/issues/17331mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2021/12/msg00015.htmlmitremailing-listx_refsource_MLIST
- www.oracle.com/security-alerts/cpuoct2021.htmlmitrex_refsource_MISC
- www.wireshark.org/security/wnpa-sec-2021-04.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.